CVE Reference: CVE-2010-4082

NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2010-4082

Description:
The viafb_ioctl_get_viafb_info function in drivers/video/via/ioctl.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a VIAFB_GET_INFO ioctl call.

CVE Status:
Candidate

References:

SUSE
  http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00004.html
  http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00001.html
  http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html
  http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html

SAID
  Secunia Advisory: SA42778
  Secunia Advisory: SA42801
  Secunia Advisory: SA42932
  Secunia Advisory: SA42890

REDHAT
  http://www.redhat.com/support/errata/RHSA-2011-0007.html
  http://www.redhat.com/support/errata/RHSA-2010-0958.html

MLIST
  http://www.openwall.com/lists/oss-security/2010/10/25/3
  http://www.openwall.com/lists/oss-security/2010/10/06/6
  http://www.openwall.com/lists/oss-security/2010/10/07/1
  http://www.openwall.com/lists/oss-security/2010/09/25/2
  http://lkml.indiana.edu/hypermail//linux/kernel/1009.1/03392.html

CONFIRM
  http://www.kernel.org/pub/linux/kernel/v2.6/testing/v2.6.36/ChangeLog-2.6.36-rc5
  http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=b4aaa78f4c2f9cde2f335b14f4ca30b01f9651ca

BID
  43817


Return to the previous page.