|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2004-0228: cpufreq_procctl casting issue | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Sebastian Krahmer <krahmer> |
| Component: | Incidents | Assignee: | Sebastian Krahmer <krahmer> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Major | ||
| Priority: | P3 - Medium | CC: | security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | CVE-2004-0228: CVSS v2 Base Score: 7.2 (AV:L/AC:L/Au:N/C:C/I:C/A:C) | ||
| Found By: | --- | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Attachments: | Fix | ||
|
Description
Sebastian Krahmer
2004-04-14 17:23:21 UTC
<!-- SBZ_reproduce --> ... CAN-2004-0228 No publication date known yet. Hubert, Andi, that means that the fix for this must not be included yet. Adding agruen to Cc:. Do we have a patch for this? From initial advisory: "To fix, use unsigned ints instead of signed.". I think he is speaking of "len" and "left". Created attachment 18491 [details]
Fix
Do you agree this is the correct fix?
Yes Sebastian, are you sure this is public as you wrote in your mail to prjmgr? I just commited the fix to CVS ... From Sebastian's mail (Fri, 23 Apr 2004 15:53:34 +0200 (CEST)): #38898 - cpu_freq int overflow + fix available + not yet public, but no timeline + should make it into updates He said that it is not public. I am sorry for the confusion. Its not really public, but the bug has no timeline. We can publish it when we find it is necessary. So it is ok if it is in CVS. CAN-2004-0228 Kernels have been submitted and are waiting for check in. kernels are approved and announced. CVE-2004-0228: CVSS v2 Base Score: 7.2 (AV:L/AC:L/Au:N/C:C/I:C/A:C) |