summaryrefslogtreecommitdiffstats
path: root/retired/CVE-2006-5174
blob: 1048181944824127f2d79174f63a6694dc70ee7d (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
Candidate: CVE-2006-5174 
References: 
 http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=52149ba6b0ddf3e9d965257cc0513193650b3ea8
Description: 
 The copy_from_user function in the uaccess code in Linux kernel 2.6
 before 2.6.19-rc1, when running on s390, does not properly clear a
 kernel buffer, which allows local user space programs to read
 portions of kernel memory by "appending to a file from a bad
 address," which triggers a fault that prevents the unused memory from
 being cleared in the kernel buffer. 
Ubuntu-Description:
Notes: 
 jmm> Fix from 2.6.18-3 was reverted, caused problems
Bugs: 
upstream: released (2.6.18.1)
linux-2.6: needed
2.6.8-sarge-security: released (2.6.8-16sarge6) [s390-uaccess-memleak.dpatch]
2.4.27-sarge-security: released (2.4.27-10sarge5) [236_s390-uaccess-memleak.diff]
2.6.10-hoary-security: ignored
2.6.12-breezy-security: ignored
2.6.15-dapper-security: ignored
2.6.17-edgy: ignored

© 2014-2024 Faster IT GmbH | imprint | privacy policy