/[kernel-sec]/retired/CVE-2008-0007
ViewVC logotype

Contents of /retired/CVE-2008-0007

Parent Directory Parent Directory | Revision Log Revision Log


Revision 1213 - (show annotations) (download)
Thu Sep 4 22:49:10 2008 UTC (4 years, 9 months ago) by dannf
File size: 1086 byte(s)
i'm tired of typing "etchnhalf"
1 Candidate: CVE-2008-0007
2 Description:
3 Linux kernel before 2.6.22.17, when using certain drivers that register
4 a fault handler that does not perform range checks, allows local users
5 to access kernel memory via an out-of-range offset.
6 References:
7 Ubuntu-Description:
8 It was discovered that some device driver fault handlers did not
9 correctly verify memory ranges. A local attacker could exploit this
10 to access sensitive kernel memory, possibly leading to a loss of privacy.
11 Notes:
12 Bugs:
13 upstream: released (2.6.24.1)
14 linux-2.6: released (2.6.24-4)
15 2.6.18-etch-security: released (2.6.18.dfsg.1-18etch2) [bugfix/mmap-VM_DONTEXPAND.patch]
16 2.6.24-etch-security: released (2.6.24-4) [bugfix/all/stable/2.6.24.1.patch]
17 2.6.8-sarge-security: released (2.6.8-17sarge1) [mmap-VM_DONTEXPAND.dpatch]
18 2.4.27-sarge-security: released (2.4.27-10sarge6) [264_mmap-VM_DONTEXPAND.diff]
19 2.6.15-dapper-security: released (2.6.15-52.67)
20 2.6.17-edgy-security: ignored (EOL)
21 2.6.20-feisty-security: released (2.6.20-17.36)
22 2.6.22-gutsy-security: released (2.6.22-15.54)
23 2.6.24-hardy-security: N/A

Properties

Name Value
svn:mergeinfo

  ViewVC Help
Powered by ViewVC 1.1.5