From 67b761de6fb66466618546e960ed867557c412ca Mon Sep 17 00:00:00 2001 From: Micah Anderson Date: Tue, 23 Feb 2010 00:41:08 +0000 Subject: fixed ioctl call, and justified paragraphs git-svn-id: svn+ssh://svn.debian.org/svn/kernel-sec@1743 e094ebfe-e918-0410-adfb-c712417f3574 --- dsa-texts/2.6.18.dfsg.1-26etch2 | 24 +++++++++++++----------- 1 file changed, 13 insertions(+), 11 deletions(-) (limited to 'dsa-texts/2.6.18.dfsg.1-26etch2') diff --git a/dsa-texts/2.6.18.dfsg.1-26etch2 b/dsa-texts/2.6.18.dfsg.1-26etch2 index ae0738f23..f32d28769 100644 --- a/dsa-texts/2.6.18.dfsg.1-26etch2 +++ b/dsa-texts/2.6.18.dfsg.1-26etch2 @@ -14,13 +14,14 @@ CVE Id(s) : CVE-2009-3080 CVE-2009-3726 CVE-2009-4005 CVE-2009-4020 Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or privilege escalation. The Common -Vulnerabilities and Exposures project identifies the following problems: +Vulnerabilities and Exposures project identifies the following +problems: CVE-2009-3080 Dave Jones reported an issue in the gdth SCSI driver. A missing - check for negative offsets in ioctl called could be exploited - by local users to create a denial of service or potentially gain + check for negative offsets in an ioctl call could be exploited by + local users to create a denial of service or potentially gain elevated privileges. CVE-2009-3726 @@ -31,16 +32,17 @@ CVE-2009-3726 CVE-2009-4005 - Roel Kluin discovered an issue in the hfc_usb driver, an ISDN driver - for Colognechip HFC-S USB chip. A potential read overflow exists which - may allow remote users to cause a denial of service condition (oops). + Roel Kluin discovered an issue in the hfc_usb driver, an ISDN + driver for Colognechip HFC-S USB chip. A potential read overflow + exists which may allow remote users to cause a denial of service + condition (oops). CVE-2009-4020 Amerigo Wang discovered an issue in the HFS filesystem that would - allow a denial of service by a local user who has sufficient privileges - to mount a specially crafted filesystem. + allow a denial of service by a local user who has sufficient + privileges to mount a specially crafted filesystem. CVE-2009-4021 @@ -76,9 +78,9 @@ CVE-2010-0415 CVE-2010-0622 - Jermome Marchand reported an issue in the futex subsystem - that allows a local user to force an invalid futex state - which results in a denial of service (oops). + Jermome Marchand reported an issue in the futex subsystem that + allows a local user to force an invalid futex state which results + in a denial of service (oops). For the oldstable distribution (etch), this problem has been fixed in version 2.6.18.dfsg.1-26etch2. -- cgit v1.2.3