PT-2006-7591 · Opensuse+2 · Opensuse+2
Publicado
1970-01-01
·
Atualizado
2018-10-30
·
CVE-2006-0744
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel before 2.6.16.5
openSUSE (affected versions not specified)
Description
The issue is related to the Linux kernel and multiple packages in the openSUSE operating system. The Linux kernel does not properly handle uncanonical return addresses on Intel EM64T CPUs, which can cause the kernel exception handler to run on the user stack with the wrong GS. The openSUSE packages have multiple vulnerabilities that can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations
For Linux kernel before 2.6.16.5, update to a version 2.6.16.5 or later.
For openSUSE, since the affected versions are not specified, it is recommended to check the official openSUSE website for the latest security updates and apply them accordingly. Additionally, consider restricting access to the vulnerable packages until a patch is available.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Linux Kernel
Red Hat
Opensuse