PT-2008-6867 · Linux+1 · Linux Kernel+1

Jan Kratochvil

·

Publicado

1970-01-01

·

Atualizado

2017-09-29

·

CVE-2008-1514

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.27-rc6 linux-image-2.6.24-etchnhalf.1-sb1-bcm91250a linux-image-2.6.24-etchnhalf.1-s390-tape linux-headers-2.6.24-etchnhalf.1-all-ia64 linux-image-2.6.24-etchnhalf.1-parisc-smp linux-headers-2.6.24-etchnhalf.1-itanium linux-image-2.6.24-etchnhalf.1-r5k-cobalt linux-headers-2.6.24-etchnhalf.1-parisc64 linux-headers-2.6.24-etchnhalf.1-amd64 linux-image-2.6.24-etchnhalf.1-iop32x linux-manual-2.6.24 linux-headers-2.6.24-etchnhalf.1-all-amd64 linux-image-2.6.24-etchnhalf.1-sparc64-smp linux-image-2.6.24-etchnhalf.1-alpha-smp linux-image-2.6.24-etchnhalf.1-sparc64 linux-image-2.6.24-etchnhalf.1-amd64 linux-image-2.6.24-etchnhalf.1-686 linux-image-2.6.24-etchnhalf.1-powerpc linux-doc-2.6.24 linux-support-2.6.24-etchnhalf.1 linux-source-2.6.24 linux-headers-2.6.24-etchnhalf.1-powerpc-miboot linux-image-2.6.24-etchnhalf.1-alpha-legacy linux-image-2.6.24-etchnhalf.1-powerpc64 linux-image-2.6.24-etchnhalf.1-powerpc-smp linux-image-2.6.24-etchnhalf.1-alpha-generic linux-headers-2.6.24-etchnhalf.1-all-arm linux-image-2.6.24-etchnhalf.1-parisc64-smp linux-headers-2.6.24-etchnhalf.1-footbridge linux-headers-2.6.24-etchnhalf.1-all-i386 linux-headers-2.6.24-etchnhalf.1-all-sparc linux-image-2.6.24-etchnhalf.1-footbridge linux-image-2.6.24-etchnhalf.1-powerpc-miboot linux-headers-2.6.24-etchnhalf.1-alpha-legacy linux-image-2.6.24-etchnhalf.1-686-bigmem linux-image-2.6.24-etchnhalf.1-parisc64 linux-image-2.6.24-etchnhalf.1-s390 linux-headers-2.6.24-etchnhalf.1-powerpc64 linux-headers-2.6.24-etchnhalf.1-parisc-smp linux-image-2.6.24-etchnhalf.1-mckinley linux-headers-2.6.24-etchnhalf.1-sparc64-smp linux-image-2.6.24-etchnhalf.1-486 linux-headers-2.6.24-etchnhalf.1-sb1-bcm91250a linux-patch-debian-2.6.24 linux-tree-2.6.24 linux-headers-2.6.24-etchnhalf.1-sparc64 linux-headers-2.6.24-etchnhalf.1-r5k-cobalt linux-headers-2.6.24-etchnhalf.1-powerpc-smp linux-image-2.6.24-etchnhalf.1-parisc linux-headers-2.6.24-etchnhalf.1-all-alpha linux-headers-2.6.24-etchnhalf.1-sb1a-bcm91480b linux-headers-2.6.24-etchnhalf.1-486 linux-headers-2.6.24-etchnhalf.1-all-hppa linux-headers-2.6.24-etchnhalf.1-686 linux-headers-2.6.24-etchnhalf.1-all-powerpc linux-image-2.6.24-etchnhalf.1-sb1a-bcm91480b linux-headers-2.6.24-etchnhalf.1-powerpc linux-image-2.6.24-etchnhalf.1-ixp4xx linux-headers-2.6.24-etchnhalf.1-iop32x linux-image-2.6.24-etchnhalf.1-4kc-malta linux-headers-2.6.24-etchnhalf.1-686-bigmem linux-headers-2.6.24-etchnhalf.1-common linux-image-2.6.24-etchnhalf.1-s390x linux-headers-2.6.24-etchnhalf.1-all-mipsel linux-headers-2.6.24-etchnhalf.1-alpha-smp linux-headers-2.6.24-etchnhalf.1-all-s390 linux-headers-2.6.24-etchnhalf.1-5kc-malta linux-headers-2.6.24-etchnhalf.1-s390 linux-headers-2.6.24-etchnhalf.1-ixp4xx linux-image-2.6.24-etchnhalf.1-itanium linux-headers-2.6.24-etchnhalf.1-alpha-generic linux-headers-2.6.24-etchnhalf.1-mckinley linux-headers-2.6.24-etchnhalf.1-all linux-headers-2.6.24-etchnhalf.1-parisc linux-image-2.6.24-etchnhalf.1-5kc-malta linux-headers-2.6.24-etchnhalf.1-parisc64-smp linux-headers-2.6.24-etchnhalf.1-s390x linux-headers-2.6.24-etchnhalf.1-4kc-malta
Description The issue affects the Linux kernel and various Debian GNU/Linux packages, potentially leading to a breach of confidentiality, integrity, and availability of protected information. The vulnerability in the Linux kernel, specifically in the arch/s390/kernel/ptrace.c file, allows local users to cause a denial of service (kernel panic) via the user-area-padding test from the ptrace testsuite in 31-bit mode, which triggers an invalid dereference.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-00809
BDU:2015-00810
BDU:2015-00811
BDU:2015-00812
BDU:2015-00813
BDU:2015-00814
BDU:2015-00815
BDU:2015-00816
BDU:2015-00817
BDU:2015-00818
BDU:2015-00819
BDU:2015-00820
BDU:2015-00821
BDU:2015-00822
BDU:2015-00823
BDU:2015-00824
BDU:2015-00825
BDU:2015-00826
BDU:2015-00827
BDU:2015-00828
BDU:2015-00829
BDU:2015-00830
BDU:2015-00831
BDU:2015-00832
BDU:2015-00833
BDU:2015-00834
BDU:2015-00835
BDU:2015-00836
BDU:2015-00837
BDU:2015-00838
BDU:2015-00839
BDU:2015-00840
BDU:2015-00841
BDU:2015-00842
BDU:2015-00843
BDU:2015-00844
BDU:2015-00845
BDU:2015-00846
BDU:2015-00847
BDU:2015-00848
BDU:2015-00849
BDU:2015-00850
BDU:2015-00851
BDU:2015-00852
BDU:2015-00853
BDU:2015-00854
BDU:2015-00855
BDU:2015-00856
BDU:2015-00857
BDU:2015-00858
BDU:2015-00859
BDU:2015-00860
BDU:2015-00861
BDU:2015-00862
BDU:2015-00863
BDU:2015-00864
BDU:2015-00865
BDU:2015-00866
BDU:2015-00867
BDU:2015-00868
BDU:2015-00869
BDU:2015-00870
BDU:2015-00871
BDU:2015-00872
BDU:2015-00873
BDU:2015-00874
BDU:2015-00875
BDU:2015-00876
BDU:2015-00877
BDU:2015-00878
BDU:2015-00879
BDU:2015-00880
BDU:2015-00881
BDU:2015-00882
BDU:2015-00883
BDU:2015-00884
BDU:2015-00885
CVE-2008-1514
DSA-1653-1
DSA-1655-1
RHSA-2008:0972
RHSA-2008_0972

Produtos afetados

Linux Kernel
Red Hat