|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2004-1333: kernel: local dos in tty handler | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Marcus Meissner <meissner> |
| Component: | Incidents | Assignee: | Marcus Meissner <meissner> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Major | ||
| Priority: | P3 - Medium | CC: | security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | CVE-2004-1333: CVSS v2 Base Score: 2.1 (AV:L/AC:L/Au:N/C:N/I:N/A:P) | ||
| Found By: | Other | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Attachments: |
tty2vendor.c
vtresize-26.patch vtresize-24.patch |
||
|
Description
Marcus Meissner
2004-12-13 17:19:41 UTC
<!-- SBZ_reproduce --> see attached exploit. Created attachment 26994 [details]
tty2vendor.c
exploit from georgi
Is someone working on a fix? raise a bit in prio http://linux.bkbits.net:8080/linux-2.6/diffs/drivers/char/vt.c%401.85?nav=index.html| src/.|src/drivers|src/drivers/char|hist/drivers/char/vt.c Created attachment 27902 [details]
vtresize-26.patch
Created attachment 27903 [details]
vtresize-24.patch
last 2 attachments are patches from mainline kernels. this is public Ok, I just committed the fixes to all trees except the SLES9 SP1 tree. Someone needs to decide what to do with this one... is public, so move to suselinux category I approve it to also go into the next maintenance/security update kernel. Assigning back to security-team. Apparently forgot that when adding my last comment. released for 9.1/SP1 branch. other products still missing, will in their next update round. marcus tracked CAN-2004-1333 updates and advisory released CVE-2004-1333: CVSS v2 Base Score: 2.1 (AV:L/AC:L/Au:N/C:N/I:N/A:P) |