Release date:
Updated on:
Affected Systems:
Debian Linux 5.0 x
Linux kernel 2.6.11.11-2.6.26
Description:
--------------------------------------------------------------------------------
Bugtraq id: 45074
Cve id: CVE-2010-4074
Linux Kernel is the Kernel used by open source Linux.
Linux Kernel has the information leakage vulnerability. Local attackers can exploit this vulnerability to obtain sensitive information from the Kernel stack.
The TIOCGICOUNT device ioctl in mos771200c and mos7840.c allows unauthorized users to read uninitialized stack memory, because the "Reserved" members of the serial_icounter_struct Structure Stored in the stack have not been changed or cleared before being copied back to the user State area.
<* Source: Dan Rosenberg
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Debian
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.debian.org/security/
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kernel.org/