| 1 |
Candidate: CVE-2011-1495
|
| 2 |
Description: information disclosure in mpt2ctl
|
| 3 |
References:
|
| 4 |
jmm> http://marc.info/?l=linux-scsi&m=130202237006310&w=2
|
| 5 |
jmm> The /dev file is owned by root as standard, so shouldn't be an issue
|
| 6 |
jmm> for sane installations
|
| 7 |
jmm> no upstream fix as of 2011-04-18
|
| 8 |
Notes:
|
| 9 |
Bugs:
|
| 10 |
upstream: released (2.6.39-rc6) [a1f74ae82d133ebb2aabb19d181944b4e83e9960]
|
| 11 |
2.6.32-upstream-stable: released (2.6.32.40)
|
| 12 |
sid: released (2.6.38-5)
|
| 13 |
2.6.26-lenny-security: N/A "code not present"
|
| 14 |
2.6.32-squeeze-security: released (2.6.32-34) [bugfix/all/mpt2sas-prevent-heap-overflows-and-unchecked-reads.patch]
|