Bug 62595 (CVE-2004-0685) - VUL-0: CVE-2004-0685 :kernel: USB drivers use uninitialized memory
Summary: VUL-0: CVE-2004-0685 :kernel: USB drivers use uninitialized memory
Status: RESOLVED FIXED
Alias: CVE-2004-0685
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: All Linux
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Hubert Mantel
QA Contact: Security Team bot
URL:
Whiteboard: CVE-2004-0685: CVSS v2 Base Score: 4....
Keywords:
Depends on:
Blocks:
 
Reported: 2004-10-25 21:34 UTC by Thomas Biege
Modified: 2021-10-16 09:04 UTC (History)
5 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
usb-leak.txt (2.67 KB, text/plain)
2004-10-25 21:39 UTC, Thomas Biege
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Biege 2004-10-25 21:34:45 UTC
Hello, 
please have a look at: 
	http://www.kb.cert.org/vuls/id/981134 
 
The bug seems to be from August and Gentoo released updates. 
Therefore a patch should be available... maybe we already have 
it in the source.
Comment 1 Thomas Biege 2004-10-25 21:34:45 UTC
<!-- SBZ_reproduce  -->
-
Comment 2 Thomas Biege 2004-10-25 21:39:09 UTC
Created attachment 25371 [details]
usb-leak.txt

Mail from vendor-sec@
Comment 3 Thomas Biege 2004-10-25 21:46:52 UTC
Oops, this mail is from 2003. :-\ 
Comment 4 Thomas Biege 2004-10-25 22:00:04 UTC
From: Mark J Cox <mjc@redhat.com> 
To: Thomas Biege <thomas@suse.de> 
Cc: vendor-sec@lst.de 
Subject: Re: [vendor-sec] kernel usb driver leak memory 
Errors-To: vendor-sec-admin@lst.de 
Date: Mon, 25 Oct 2004 13:55:42 +0100 (BST) 
 
>       http://www.kb.cert.org/vuls/id/981134 
 
Is that: 
 
CAN-2004-0685 usb sparse fixes in 2.4 {MODERATE} 
        More leaks found by Conectiva mentioned to vendor sec on Oct23, 
 
        Fixed upstream 20031023 therefore 2.6.0 wasn't vulnerable 
 
http://linux.bkbits.net:8080/linux-2.6/cset@3f986b35LyBKc-OxB8G6k22oOjgYTQ 
 
        Fixed on 20040726 by: 
 
http://linux.bkbits.net:8080/linux-2.4/cset@410582380U3H9KOx8J2YZmMT0bhXQw 
 
Comment 5 Hubert Mantel 2004-10-29 23:21:53 UTC
Sorry, I do not know how to work with BitKeeper and I plainly refuse to learn
how to use this proprietary repository. Can somebody please send me the patches
in some usable form?
Comment 6 Olaf Hering 2004-10-30 00:09:52 UTC
its called ' diff -Nur style patch ' in the links above.
Comment 7 Olaf Hering 2004-10-30 00:24:05 UTC
fixed.
Comment 8 Thomas Biege 2009-10-13 19:54:37 UTC
CVE-2004-0685: CVSS v2 Base Score: 4.6 (AV:L/AC:L/Au:N/C:P/I:P/A:P)