Release date:
Updated on:
Affected Systems:
Linux kernel 2.6.0-2.6.37
Description:
--------------------------------------------------------------------------------
Bugtraq id: 45054
Cve id: CVE-2010-4072
Linux Kernel is the Kernel used by open source Linux.
Linux Kernel has a vulnerability in implementation. Local attackers can exploit this vulnerability to obtain sensitive information, which may assist in other attacks.
Copying the shmid_ds structure to the user-state region where shm_unused {, 2, 3} is not initialized may cause leakage of the kernel stack memory content.
<* Source: Vasiliy Kulikov
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kernel.org/