SuSE Security Announcement - A problem exists in the Linux kernel 2.4 and 2.6 series where missing Discretionary Access Control (DAC) in the chown(2) system call allow an attacker with a local account the ability to change the group ownership of arbitrary files.
016299baba8db03cb7e0aa77aab766ca6012636db94e2bb330a1d595585702a8