From cffb363c568e15bb95549d0c5746068cca9c94bf Mon Sep 17 00:00:00 2001 From: dann frazier Date: Sun, 20 Jul 2008 21:58:00 +0000 Subject: Debian updates; retire several issues git-svn-id: svn+ssh://svn.debian.org/svn/kernel-sec@1197 e094ebfe-e918-0410-adfb-c712417f3574 --- retired/CVE-2007-3513 | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) create mode 100644 retired/CVE-2007-3513 (limited to 'retired/CVE-2007-3513') diff --git a/retired/CVE-2007-3513 b/retired/CVE-2007-3513 new file mode 100644 index 00000000..9bd02927 --- /dev/null +++ b/retired/CVE-2007-3513 @@ -0,0 +1,19 @@ +Candidate: CVE-2007-3513 +References: +Description: + The lcd_write function in drivers/usb/misc/usblcd.c in the Linux kernel + before 2.6.22-rc7 does not limit the amount of memory used by a caller, + which allows local users to cause a denial of service (memory consumption). +Ubuntu-Description: + A flaw was discovered in the usblcd driver. A local attacker could cause + large amounts of kernel memory consumption, leading to a denial of service. +Notes: +Bugs: +upstream: released (2.6.22-rc7) +linux-2.6: released (2.6.22-1) +2.6.18-etch-security: released (2.6.18.dfsg.1-13etch1) [bugfix/usblcd-limit-memory-consumption.patch] +2.6.8-sarge-security: ignored (2.6.8-17sarge1) "Too different" +2.4.27-sarge-security: ignored (2.4.27-10sarge6) "Too different" +2.6.15-dapper-security: released (2.6.15-28.57) +2.6.17-edgy-security: released (2.6.17.1-12.40) [85816b5fa3476f3fcf7758a1bd338d69184085d7] +2.6.20-feisty-security: released (2.6.20-16.31) [165018c61779a357d33947a2ae169148b6ab8d9f] -- cgit v1.2.3