PT-2015-4295 · Linux+5 · Linux Kernel+5

Publicado

2015-01-09

·

Atualizado

2020-05-21

·

CVE-2014-9585

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 3.18.2
Description The issue concerns the vdso addr function in the Linux kernel, which does not properly choose memory locations for the vDSO area. This makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end of a PMD.
Recommendations For Linux kernel versions through 3.18.2, update to a version that contains a fix for this issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

ALT-PU-2015-1058
ALT-PU-2015-1794
CESA-2015_1081
CESA-2015_1778
CVE-2014-9585
DLA-155-1
DSA-3170-1
MGASA-2015-0070
MGASA-2015-0075
MGASA-2015-0076
MGASA-2015-0077
MGASA-2015-0078
OPENSUSE-SU-2015_0713-1
OPENSUSE-SU-2015_0714-1
RHSA-2015:1081
RHSA-2015:1778
RHSA-2015:1787
RHSA-2015:1788
RHSA-2015_1081
RHSA-2015_1778
RHSA-2015_1788
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0652-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2513-1
USN-2514-1
USN-2515-1
USN-2516-1
USN-2516-2
USN-2516-3
USN-2517-1
USN-2518-1

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu