|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
[SA11626] Linux Kernel e1000 Network Driver Kernel Memory Disclosure Vulnerability
From: Secunia Security Advisories (sec-adv
secunia.com)
Date: Fri May 21 2004 - 07:22:09 CDT
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
TITLE:
Linux Kernel e1000 Network Driver Kernel Memory Disclosure
Vulnerability
SECUNIA ADVISORY ID:
SA11626
VERIFY ADVISORY:
http://secunia.com/advisories/11626/
CRITICAL:
Less critical
IMPACT:
Exposure of sensitive information
WHERE:
Local system
OPERATING SYSTEM:
Linux Kernel 2.4.x
Linux Kernel 2.6.x
DESCRIPTION:
A vulnerability has been discovered in the Linux kernel, potentially
allowing malicious, local users to gain knowledge of sensitive
information.
The e1000 ethernet driver reportedly uses the "copy_to_user()"
function insecurely when copying data from kernel space into
userspace. This can be exploited to disclose an arbitrary amount of
kernel memory.
Another kernel memory disclosure issue has also been reported in the
WAN SDLA driver. However, exploitation requires the CAP_NET_ADMIN
capability (usually just held by the "root" user).
SOLUTION:
The vulnerability has been fixed in versions 2.6.6 and 2.4.27-pre1.
http://kernel.org/
PROVIDED AND/OR DISCOVERED BY:
Ken Ashcraft
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
----------------------------------------------------------------------
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]