Secunia Logo
 
CVE Reference: CVE-2007-6417
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-6417

Description:
The shmem_getpage function (mm/shmem.c) in Linux kernel 2.6.11 through 2.6.23 does not properly clear allocated memory in some rare circumstances related to tmpfs, which might allow local users to read sensitive kernel data or cause a denial of service (crash).

CVE Status:
Candidate

References:

UBUNTU
  http://www.ubuntu.com/usn/usn-578-1
  http://www.ubuntu.com/usn/usn-574-1

SUSE
  http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.html

SAID
  Secunia Advisory: SA28141
  Secunia Advisory: SA28706
  Secunia Advisory: SA28806
  Secunia Advisory: SA28971
  Secunia Advisory: SA32023

REDHAT
  http://www.redhat.com/support/errata/RHSA-2008-0885.html

OSVDB
  44120

MLIST
  http://marc.info/?l=linux-kernel&m=119743651829347&w=2
  http://marc.info/?l=linux-kernel&m=119769771026243&w=2
  http://marc.info/?l=linux-kernel&m=119627664702379&w=2

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDVSA-2008:112
  http://www.mandriva.com/security/advisories?name=MDVSA-2008:086

DEBIAN
  http://www.debian.org/security/2007/dsa-1436

BID
  27694


Return to the previous page.