Candidate: CVE-2005-0003 References: CONFIRM:http://linux.bkbits.net:8080/linux-2.4/cset@41c36fb6q1Z68WUzKQFjJR-40Ev3tw MANDRAKE:MDKSA-2005:022 URL:http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022 REDHAT:RHSA-2005:043 URL:http://www.redhat.com/support/errata/RHSA-2005-043.html SUSE:SUSE-SA:2005:018 URL:http://www.novell.com/linux/security/advisories/2005_18_kernel.html TRUSTIX:2005-0001 URL:http://www.trustix.org/errata/2005/0001/ MISC:http://linux.bkbits.net:8080/linux-2.6/cset@41a6721cce-LoPqkzKXudYby_3TUmg BID:12261 URL:http://www.securityfocus.com/bid/12261 XF:linux-vma-gain-privileges(18886) URL:http://xforce.iss.net/xforce/xfdb/18886 Description: The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file. Notes: Bugs: upstream: released (2.6.10) linux-2.6: N/A 2.6.8-sarge-security: released (2.6.8-11) [binfmt-huge-vma-dos2.dpatch] 2.4.27-sarge-security: released (2.4.27-9) [145_insert_vm_struct-no-BUG.patch] 2.4.19-woody-security: released (2.4.19-4.woody3) 2.4.18-woody-security: released (2.4.18-14.4) 2.4.17-woody-security: released (2.4.17-1woody4) 2.4.16-woody-security: released (2.4.16-1woody3) 2.4.17-woody-security-hppa: released (32.5) 2.4.17-woody-security-ia64: released (011226.18) 2.4.18-woody-security-hppa: released (62.4)