/[kernel-sec]/retired/CVE-2006-1524
ViewVC logotype

Contents of /retired/CVE-2006-1524

Parent Directory Parent Directory | Revision Log Revision Log


Revision 566 - (show annotations) (download)
Sun Aug 27 03:29:50 2006 UTC (6 years, 8 months ago) by dannf
File size: 947 byte(s)
the original issue was split into two advisories - we'd already fixed 2071
in sarge, but had it makred as 1524. corrections..
1 Candidate: CVE-2006-1524
2 References:
3 CONFIRM:http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.6
4 BID:17587
5 URL:http://www.securityfocus.com/bid/17587
6 SECUNIA:19664
7 URL:http://secunia.com/advisories/19664
8 SECUNIA:19657
9 URL:http://secunia.com/advisories/19657
10 Description:
11 madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow
12 file and mmap restrictions, which allows local users to bypass IPC
13 permissions and replace portions of readonly tmpfs files with zeroes,
14 aka the MADV_REMOVE vulnerability. NOTE: this description was
15 originally written in a way that combined two separate issues. The
16 mprotect issue now has a separate name, CVE-2006-2071.
17 Notes:
18 Bugs:
19 upstream: released (2.6.16.7)
20 linux-2.6:
21 2.6.8-sarge-security: N/A
22 2.4.27-sarge-security: N/A
23 2.4.19-woody-security:
24 2.4.18-woody-security:
25 2.4.17-woody-security:
26 2.4.16-woody-security:
27 2.4.17-woody-security-hppa:
28 2.4.17-woody-security-ia64:

  ViewVC Help
Powered by ViewVC 1.1.5