[Secure-testing-commits] r3214 - data/CVE

Moritz Muehlenhoff jmm-guest at costa.debian.org
Tue Jan 3 15:58:38 UTC 2006


Author: jmm-guest
Date: 2006-01-03 15:58:32 +0000 (Tue, 03 Jan 2006)
New Revision: 3214

Modified:
   data/CVE/list
Log:
new kernel information leak


Modified: data/CVE/list
===================================================================
--- data/CVE/list	2006-01-03 12:07:21 UTC (rev 3213)
+++ data/CVE/list	2006-01-03 15:58:32 UTC (rev 3214)
@@ -1,3 +1,7 @@
+CVE-2005-4605 [kernel procfs information leak]
+	- linux-2.6 <unfixed>
+	- kernel-source-2.4.27 <not-affected> (2.4's proc_file_lseek contains a sanity check)
+	NOTE: Sarge 2.6.8 status yet unclear
 CVE-2005-XXXX [xshisen follows symlinks for shared gid games files]
 	- xshisen 1.51-1-1.2 (bug #291613)
 CVE-2006-0062 [Potential xlockmore bypass]




More information about the Secure-testing-commits mailing list