FS#41231 - [linux] [linux-lts] CVE-2014-4943: Linux privilege escalation in ppp over l2tp sockets

Attached to Project: Arch Linux
Opened by Daniel Micay (thestinger) - Thursday, 17 July 2014, 06:41 GMT
Last edited by Dave Reisner (falconindy) - Friday, 08 August 2014, 15:24 GMT
Task Type Bug Report
Category Security
Status Closed
Assigned To Tobias Powalowski (tpowa)
Thomas Bächler (brain0)
Andreas Radke (AndyRTR)
Bartłomiej Piotrowski (Barthalion)
Architecture All
Severity Critical
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 2
Private No
This task depends upon

Closed by  Dave Reisner (falconindy)
Friday, 08 August 2014, 15:24 GMT
Reason for closing:  Fixed
Additional comments about closing:  Patch for CVE-2014-4943 is included in 3.14.16 and upstream.
Comment by Daniel Micay (thestinger) - Saturday, 02 August 2014, 06:25 GMT
The fix for this is going to be in 3.16, but I don't see it in 3.15...
Comment by Claire Farron (clfarron4) - Thursday, 07 August 2014, 22:47 GMT
Patch has been applied in 3.10.52.

Included in 3.14.16-rc: http://www.spinics.net/linux/lists/kernel/msg1801217.html
Included in 3.15.9-rc: http://www.spinics.net/linux/lists/kernel/msg1801299.html

Loading...