PT-2005-4087 · Linux+1 · Linux+1
Blaisorblade
+1
·
Published
2005-10-20
·
Updated
2018-10-19
·
CVE-2005-3276
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Linux versions prior to 2.6.12.4 and 2.6.13
Description
The issue is related to the
sys get thread area function in process.c, which does not properly clear a data structure before copying it to userspace. This might allow a user process to obtain sensitive information.Recommendations
For Linux versions prior to 2.6.12.4, update to version 2.6.12.4 or later.
For Linux version 2.6.13, no specific fix is provided, however, updating to a later version may mitigate the risk.
As a temporary workaround, consider restricting access to the
sys get thread area function until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux
Red Hat