SB2006013101 - Improper input validation in Linux kernel
Published: January 31, 2006
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper input validation (CVE-ID: CVE-2006-0482)
The vulnerability allows a local user to perform service disruption.
Linux kernel 2.6.15.1 and earlier, when running on SPARC architectures, allows local users to cause a denial of service (hang) via a 'date -s' command, which causes invalid sign extended arguments to be provided to the get_compat_timespec function call.
Remediation
Install update from vendor's website.
References
- http://lists.debian.org/debian-sparc/2006/01/msg00129.html
- http://marc.info/?l=linux-sparc&m=113861010514065&w=2
- http://marc.info/?l=linux-sparc&m=113861287813463&w=2
- http://secunia.com/advisories/19374
- http://www.debian.org/security/2006/dsa-1017
- http://www.securityfocus.com/bid/17216
- http://www.vupen.com/english/advisories/2006/0418
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24475