Secunia Logo
 
CVE Reference: CVE-2005-3276
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-3276

Description:
The sys_get_thread_area function in process.c in Linux 2.6 before 2.6.12.4 and 2.6.13 does not clear a data structure before copying it to userspace, which might allow a user process to obtain sensitive information.

CVE Status:
Candidate

References:

UBUNTU
  http://www.ubuntulinux.org/support/documentation/usn/usn-219-1

SAID
  Secunia Advisory: SA19252
  Secunia Advisory: SA18510
  Secunia Advisory: SA18056
  Secunia Advisory: SA17826

REDHAT
  http://www.redhat.com/support/errata/RHSA-2006-0144.html
  http://www.redhat.com/support/errata/RHSA-2006-0101.html

MANDRIVA
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:220
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:219

MANDRAKE
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:219
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:220
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:218

FEDORA
  http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/428058/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/428028/100/0/threaded

DEBIAN
  http://www.debian.org/security/2005/dsa-922

CONFIRM
  http://lkml.org/lkml/2005/8/3/36
  http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=71ae18ec690953e9ba7107c7cc44589c2cc0d9f1
  http://linux.bkbits.net:8080/linux-2.6/cset@42e81864gSEM90Oun0jA8dufpM3inw

BID
  15527


Return to the previous page.