/[kernel-sec]/retired/CVE-2009-1046
ViewVC logotype

Contents of /retired/CVE-2009-1046

Parent Directory Parent Directory | Revision Log Revision Log


Revision 1530 - (show annotations) (download)
Tue Oct 20 21:46:22 2009 UTC (3 years, 6 months ago) by jmm
File size: 1327 byte(s)
retire more issues
1 Candidate: CVE-2009-1046
2 Description:
3 The console selection feature in the Linux kernel 2.6.28 before
4 2.6.28.4, 2.6.25, and possibly earlier versions, when the UTF-8
5 console is used, allows physically proximate attackers to cause
6 a denial of service (memory corruption) by selecting a small
7 number of 3-byte UTF-8 characters, which triggers an "an
8 off-by-two memory error." NOTE: it is not clear whether this issue
9 crosses privilege boundaries.
10 References:
11 http://lists.openwall.net/linux-kernel/2009/01/30/333
12 http://lists.openwall.net/linux-kernel/2009/02/02/364
13 http://www.openwall.com/lists/oss-security/2009/02/12/10
14 http://www.openwall.com/lists/oss-security/2009/02/12/11
15 http://www.openwall.com/lists/oss-security/2009/02/12/9
16 http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.4
17 Ubuntu-Description:
18 Notes:
19 Bugs:
20 upstream: released (2.6.28.4, 2.5.29-rc4)
21 linux-2.6: released (2.6.29-1)
22 2.6.18-etch-security: N/A "Appears to have been introduced by 759448f in 2.6.23-rc1"
23 2.6.24-etch-security: released (2.6.24-6~etchnhalf.8etch1) [bugfix/all/fix-off-by-2-error-in-console-selection.patch]
24 2.6.26-lenny-security: released (2.6.26-15lenny1) [bugfix/all/fix-off-by-2-error-in-console-selection.patch]
25 2.6.15-dapper-security:
26 2.6.22-gutsy-security:
27 2.6.24-hardy-security:
28 2.6.27-intrepid-security:

  ViewVC Help
Powered by ViewVC 1.1.5