#VU99910 Improper input validation in Linux kernel - CVE-2006-0482
Published: January 31, 2006 / Updated: July 20, 2017
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to perform service disruption.
Linux kernel 2.6.15.1 and earlier, when running on SPARC architectures, allows local users to cause a denial of service (hang) via a 'date -s' command, which causes invalid sign extended arguments to be provided to the get_compat_timespec function call.
Remediation
External links
- http://lists.debian.org/debian-sparc/2006/01/msg00129.html
- http://marc.info/?l=linux-sparc&m=113861010514065&w=2
- http://marc.info/?l=linux-sparc&m=113861287813463&w=2
- http://secunia.com/advisories/19374
- http://www.debian.org/security/2006/dsa-1017
- http://www.securityfocus.com/bid/17216
- http://www.vupen.com/english/advisories/2006/0418
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24475