Candidate: CVE-2005-4618 References: http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15 http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=8febdd85adaa41fa1fc1cb31286210fc2cd3ed0c Description: Buffer overflow in sysctl in the Linux Kernel 2.6 before 2.6.15 allows local users to cause a denial of service and possibly execute arbitrary code via a long string, which causes sysctl to write a zero byte outside the buffer. Notes: jmm> Discovered by Yi Ying Bugs: upstream: released (2.6.15) linux-2.6: released (2.6.15-1) 2.6.8-sarge-security: released (2.6.8-16sarge2) 2.4.27-sarge-security: released (2.4.27-10sarge2) 2.4.19-woody-security: 2.4.18-woody-security: 2.4.17-woody-security: 2.4.16-woody-security: 2.4.17-woody-security-hppa: 2.4.17-woody-security-ia64: