Release date: 2012-10-09
Updated on:
Affected Systems:
Linux kernel 3.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 55855
Cve id: CVE-2012-0957
Linux Kernel is the Kernel of the Linux operating system.
Linux Kernel has the local information leakage vulnerability. When an error occurs when the system information structure is calculated after the "uname ()" system is called, a local attacker can exploit the UNAME26 execution interval to obtain the Kernel stack memory.
<* Source: Brad Spengler (spender@grsecurity.net)
Link: http://secunia.com/advisories/50895/
Https://lkml.org/lkml/2012/10/9/550
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.kernel.org/