Secunia Logo
 
CVE Reference: CVE-2005-3181
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-3181

Description:
The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a memory leak that allows attackers to cause a denial of service (memory consumption).

CVE Status:
Candidate

References:

UBUNTU
  http://www.ubuntu.com/usn/usn-199-1

SUSE
  http://www.securityfocus.com/advisories/9806

SAID
  Secunia Advisory: SA17364
  Secunia Advisory: SA17917
  Secunia Advisory: SA17114
  Secunia Advisory: SA17280
  Secunia Advisory: SA17826
  Secunia Advisory: SA19374

REDHAT
  http://www.redhat.com/support/errata/RHSA-2005-808.html

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDKSA-2005:235
  http://www.mandriva.com/security/advisories?name=MDKSA-2005:220
  http://www.mandriva.com/security/advisories?name=MDKSA-2005:219

MANDRAKE
  http://www.mandriva.com/security/advisories?name=MDKSA-2005:220
  http://www.mandriva.com/security/advisories?name=MDKSA-2005:219
  http://www.mandriva.com/security/advisories?name=MDKSA-2005:218

FEDORA
  http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded
  http://www.securityfocus.com/advisories/9549

DEBIAN
  http://www.debian.org/security/2006/dsa-1017

CONFIRM
  http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=829841146878e082613a49581ae252c071057c23
  http://linux.bkbits.net:8080/linux-2.6/cset@4346883bQBeBd26syWTKX2CVC5bDcA

BID
  15076


Return to the previous page.