Out-of-bounds write in Linux kernel - CVE-2001-1399
Published: April 17, 2001 / Updated: December 8, 2016
Vulnerability identifier: #VU95668
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2001-1399
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to corrupt data.
Certain operations in Linux kernel before 2.2.19 on the x86 architecture copy the wrong number of bytes, which might allow attackers to modify memory, aka 'User access asm bug on x86.'
How to mitigate CVE-2001-1399
Install update from vendor's repository.
Sources
- http://marc.info/?l=bugtraq&m=98575345009963&w=2
- http://marc.info/?l=bugtraq&m=98637996127004&w=2
- http://marc.info/?l=bugtraq&m=98653252326445&w=2
- http://marc.info/?l=bugtraq&m=98684172109474&w=2
- http://marc.info/?l=bugtraq&m=98759029811377&w=2
- http://marc.info/?l=bugtraq&m=98775114228203&w=2
- http://marc.info/?l=bugtraq&m=99013830726309&w=2
- http://www.linux.org.uk/VERSION/relnotes.2219.html
- http://www.redhat.com/support/errata/RHSA-2001-047.html
- https://www.debian.org/security/2001/dsa-047