[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2009:233 -- Mandriva kernel

ID: oval:org.secpod.oval:def:300908Date: (C)2012-01-07   (M)2024-02-19
Class: PATCHFamily: unix




A vulnerability was discovered and corrected in the Linux 2.6 kernel: The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation on a PF_PPPOX socket

Platform:
Mandriva Linux 2008.1
Product:
kernel
Reference:
MDVSA-2009:233
CVE-2009-2692
CVE    1
CVE-2009-2692
CPE    1
cpe:/o:mandriva:linux:2008.1

© SecPod Technologies