Информационная безопасность
[RU] switch to
English Version



CVECVE-2008-5029
СтатусCandidate
ОписаниеThe __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sending an SCM_RIGHTS message through a UNIX domain socket and closing file descriptors.
PhaseAssigned (10.11.2008)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-5029
ReferencesBID : 32154
 BID : 33079
 BUGTRAQ : 20090101 Linux Kernel 2.6.18/2.6.24/2.6.20/2.6.22/2.6.21 denial of service exploit
 BUGTRAQ : 20100625 VMSA-2010-0010 ESX 3.5 third party update for Service Console kernel
 CONFIRM : https://bugzilla.redhat.com/show_bug.cgi?id=470201
 DEBIAN : DSA-1681
 DEBIAN : DSA-1687
 MANDRIVA : MDVSA-2008:234
 MISC : http://darkircop.org/unix.c
 MLIST : [linux-netdev] 20081106 UNIX sockets kernel panic
 MLIST : [oss-security] 20081106 CVE request: kernel: Unix sockets kernel panic
 OVAL : oval:org.mitre.oval:def:11694
 OVAL : oval:org.mitre.oval:def:9558
 REDHAT : RHSA-2009:0009
 REDHAT : RHSA-2009:0014
 REDHAT : RHSA-2009:0225
 REDHAT : RHSA-2009:1550
 SECTRACK : 1021292
 SECTRACK : 1021511
 SECUNIA : 32918
 SECUNIA : 32998
 SECUNIA : 33180
 SECUNIA : 33556
 SECUNIA : 33586
 SECUNIA : 33623
 SECUNIA : 33641
 SECUNIA : 33704
 SREASON : 4573
 SUSE : SUSE-SA:2008:057
 SUSE : SUSE-SA:2009:004
 SUSE : SUSE-SA:2009:008
 UBUNTU : USN-679-1
SecurityVulns:Многочисленные уязвимости безопасности в ядре Linux
 DoS против ядра Linux

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server