Secunia Logo
 
CVE Reference: CVE-2005-2800
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-2800

Description:
Memory leak in the seq_file implemenetation in the SCSI procfs interface (sg.c) in Linux kernel 2.6.13 and earlier allows local users to cause a denial of service (memory consumption) via certain repeated reads from the /proc/scsi/sg/devices file, which is not properly handled when the next() iterator returns NULL or an error.

CVE Status:
Candidate

References:

SUSE
  http://www.securityfocus.com/archive/1/archive/1/419522/100/0/threaded

SAID
  Secunia Advisory: SA17826
  Secunia Advisory: SA19374
  Secunia Advisory: SA17918
  Secunia Advisory: SA18510

REDHAT
  http://www.redhat.com/support/errata/RHSA-2006-0101.html

MANDRIVA
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:219
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:220

MANDRAKE
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:220
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:219
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:218

FEDORA
  http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded

DEBIAN
  http://www.debian.org/security/2006/dsa-1017

CONFIRM
  http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=729d70f5dfd663b44bca68a4479c96bde7e535d6

BID
  14790


Return to the previous page.