SB2004060102 - Missing release of memory after effective lifetime in Linux kernel



SB2004060102 - Missing release of memory after effective lifetime in Linux kernel

Published: June 1, 2004

Security Bulletin ID SB2004060102
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Missing release of memory after effective lifetime (CVE-ID: CVE-2004-0133)

The vulnerability allows a local user to gain access to sensitive information.

The XFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the XFS file system, which allows local users to obtain sensitive information by reading the raw device.


Remediation

Install update from vendor's website.