Bug 139565 (CVE-2005-2553) - VUL-0: CVE-2005-2553: kernel: AMD64: crash when ptracing a 64bit program with a 32bit strace/ltrace
Summary: VUL-0: CVE-2005-2553: kernel: AMD64: crash when ptracing a 64bit program with...
Status: RESOLVED FIXED
Alias: CVE-2005-2553
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Normal
Target Milestone: ---
Assignee: Marcus Meissner
QA Contact: Security Team bot
URL:
Whiteboard: affected:sles8 applied:sles8 released...
Keywords:
Depends on:
Blocks:
 
Reported: 2005-12-16 10:55 UTC by Marcus Meissner
Modified: 2019-05-07 09:45 UTC (History)
1 user (show)

See Also:
Found By: Other
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2005-12-16 10:55:17 UTC
CVE-2005-2553

The find_target function in ptrace32.c in the Linux kernel 2.4.x before 2.4.29 does not properly handle a NULL return value from another function, which allows local users to cause a denial of service (kernel crash/oops) by running a 32-bit ltrace program with the -i option on a 64-bit executable program.

http://lkml.org/lkml/2005/1/5/245 

http://linux.bkbits.net:8080/linux-2.4/cset@41dd3455GwQPufrGvBJjcUOXQa3WXA
Comment 1 Marcus Meissner 2005-12-16 10:56:47 UTC
patch looks simple enough, only SLES 8 affected.
Comment 2 Lars Marowsky-Bree 2005-12-20 11:59:51 UTC
Committed.
Comment 3 Marcus Meissner 2006-01-25 14:04:37 UTC
for tracking
Comment 4 Marcus Meissner 2006-02-27 15:48:09 UTC
updates + advisory released.
Comment 5 Klaus Wagner 2007-09-29 15:46:11 UTC
Patch:  patches.common/ltrace-32bit-on-64bit-executable-fix
 
present and released in:
   SLES8 kernel update 2.4.21-314 dated Nov 02, 2006 & released Nov 08, 2006.
(check of presence in prior updates omitted here).
 
Adding Whiteboard Status "released:" for SLES-8
Comment 6 Thomas Biege 2009-10-13 20:44:39 UTC
CVE-2005-2553: CVSS v2 Base Score: 2.1 (AV:L/AC:L/Au:N/C:N/I:N/A:P)