Release date:
Updated on: 2010-09-17
Affected Systems:
Linux kernel 2.6.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 43229
Cve id: CVE-2010-3297
Linux Kernel is the Kernel used by open source Linux.
Drivers/net/eql. the eql_g_master_cfg () function in the c driver does not properly initialize the master_name member in the master_config_t structure and then copies it to the user space. Local users can use the EQL_GETMASTRCFG ioctl request to read 16 bytes of uninitialized stack memory.
<* Source: Dan Rosenberg
Link: http://secunia.com/advisories/41440/
Https://bugzilla.redhat.com/show_bug.cgi? Format = multiple & amp; id = 633145
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://lkml.org/lkml/2010/9/11/168