[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2009:205 -- Mandriva kernel

ID: oval:org.secpod.oval:def:301215Date: (C)2012-01-07   (M)2024-02-19
Class: PATCHFamily: unix




A vulnerability was discovered and corrected in the Linux 2.6 kernel: The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation on a PF_PPPOX socket

Platform:
Mandriva Linux 2009.0
Mandriva Linux 2009.1
Product:
kernel
Reference:
MDVSA-2009:205
CVE-2009-2692
CVE    1
CVE-2009-2692
CPE    2
cpe:/o:mandriva:linux:2009.0
cpe:/o:mandriva:linux:2009.1

© SecPod Technologies