|
|
Log in / Subscribe / Register

kernel information leak

Package(s):kernel CVE #(s):CAN-2004-0415
Created:August 3, 2004 Updated:October 26, 2004
Description: Paul Starzetz discovered flaws in the Linux kernel when handling file offset pointers. These consist of invalid conversions of 64 to 32-bit file offset pointers and possible race conditions. A local unprivileged user could make use of these flaws to access large portions of kernel memory. Note that this vulnerability affects all 2.4 kernels through 2.4.26 and 2.6 kernels through 2.6.7.

A fix for this problem was added to the fifth 2.4.27 release candidate.

Alerts:
Conectiva CLA-2004:879 kernel 2004-10-26
Fedora-Legacy FLSA:1804 kernel 2004-10-18
Mandrake MDKSA-2004:087 kernel 2004-08-26
Gentoo 200408-24 kernel 2004-08-25
Whitebox WBSA-2004:413-01 kernel 2004-08-19
Red Hat RHSA-2004:327-01 kernel (Itanium) 2004-08-18
Fedora FEDORA-2004-251 kernel 2004-08-10
Trustix TSLSA-2004-0041 kernel 2004-08-09
SuSE SUSE-SA:2004:024 kernel 2004-08-09
Red Hat RHSA-2004:413-01 kernel 2004-08-03
Red Hat RHSA-2004:418-01 kernel 2004-08-03
Fedora FEDORA-2004-247 kernel 2004-08-03

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds