Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2010-2071
Description:The btrfs_xattr_set_acl function in fs/btrfs/acl.c in btrfs in the Linux kernel 2.6.34 and earlier does not check file ownership before setting an ACL, which allows local users to bypass file permissions by setting arbitrary ACLs, as demonstrated using setfacl.
Test IDs: 1.3.6.1.4.1.25623.1.0.67704   1.3.6.1.4.1.25623.1.0.67697  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2010-2071
[linux-kernel] 20100518 [PATCH] btrfs: should add a permission check for setfacl
http://lkml.org/lkml/2010/5/17/544
[oss-security] 20100611 CVE request - kernel: btrfs: prevent users from setting ACLs on files they do not own
http://www.openwall.com/lists/oss-security/2010/06/11/3
[oss-security] 20100614 Re: CVE request - kernel: btrfs: prevent users from setting ACLs on files they do not own
http://www.openwall.com/lists/oss-security/2010/06/14/2
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=2f26afba
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=2f26afba




© 1998-2025 E-Soft Inc. All rights reserved.