OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[SA11626] Linux Kernel e1000 Network Driver Kernel Memory Disclosure Vulnerability

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Fri May 21 2004 - 07:22:09 CDT


TITLE:
Linux Kernel e1000 Network Driver Kernel Memory Disclosure
Vulnerability

SECUNIA ADVISORY ID:
SA11626

VERIFY ADVISORY:
http://secunia.com/advisories/11626/

CRITICAL:
Less critical

IMPACT:
Exposure of sensitive information

WHERE:
Local system

OPERATING SYSTEM:
Linux Kernel 2.4.x
Linux Kernel 2.6.x

DESCRIPTION:
A vulnerability has been discovered in the Linux kernel, potentially
allowing malicious, local users to gain knowledge of sensitive
information.

The e1000 ethernet driver reportedly uses the "copy_to_user()"
function insecurely when copying data from kernel space into
userspace. This can be exploited to disclose an arbitrary amount of
kernel memory.

Another kernel memory disclosure issue has also been reported in the
WAN SDLA driver. However, exploitation requires the CAP_NET_ADMIN
capability (usually just held by the "root" user).

SOLUTION:
The vulnerability has been fixed in versions 2.6.6 and 2.4.27-pre1.
http://kernel.org/

PROVIDED AND/OR DISCOVERED BY:
Ken Ashcraft

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/

Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------