SB2005123112 - Improper access control in Linux kernel
Published: December 31, 2005
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper access control (CVE-ID: CVE-2005-0136)
The vulnerability allows a local user to perform service disruption.
The Linux kernel before 2.6.11 on the Itanium IA64 platform has certain 'ptrace corner cases' that allow local users to cause a denial of service (crash) via crafted syscalls, possibly related to MCA/INIT, a different vulnerability than CVE-2005-1761.
Remediation
Install update from vendor's website.
References
- http://lists.alioth.debian.org/pipermail/kernel-svn-changes/2005-August/002597.html
- http://openvz.org/news/updates/kernel-022stab045.1-released
- http://secunia.com/advisories/17002
- http://www.gelato.unsw.edu.au/archives/linux-ia64/0409/11073.html
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11
- http://www.redhat.com/support/errata/RHSA-2005-420.html
- http://www.redhat.com/support/errata/RHSA-2005-663.html
- http://www.vupen.com/english/advisories/2005/1878
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=148862
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=155283
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11628