[linux-guvenlik] A critical security vulnerability has been found in the Linux kernel memory management code inside the mremap(2

---------

From: Unix&NT/ 2000-Mäklarna (info@dck.se)
Date: Fri 20 Feb 2004 - 11:34:19 EST


http://isec.pl/vulnerabilities04.html
iSEC Security Research.

Sn meslektaslar
Release:
  February 18, 2004
Synopsis:
  Linux kernel do_mremap VMA limit local privilege escalation vulnerability
Product:
  Linux kernel 2.2 up to 2.2.25, 2.4 up to 2.4.24, 2.6 up to 2.6.2
Author:
  Paul Starzetz (<mailto:paul@isec.pl>paul@isec.pl)

A critical security vulnerability has been found in the Linux kernel memory
management code inside the mremap(2) system call due to missing function
return value check. This bug is completely unrelated to the mremap bug
disclosed on 05.01.2004 except concerning the same internal kernel function
code.

Kale CELIK

info@dck.se


---------

Bu arsiv hypermail 2.1.6 tarafindan uretilmistir.