[iSEC] Linux kernel do_brk() vulnerability details
Grok Headline matches for [iSEC] Linux kernel do_brk() vulnerability details
[iSEC] Linux kernel do_brk() lacks
argument bound checking
[iSEC] Linux kernel do_brk() lacks
argument bound checking
12/02/2003 01:28 PMPaul Starzetz (Dec 01 2003)
[cliph@isec.pl: Linux kernel setsockopt
MCAST_MSFILTER integer overflow]
[cliph@isec.pl: Linux kernel setsockopt
MCAST_MSFILTER integer overflow]
04/20/2004 06:18 PMDavid Ahmad (Apr 20 2004)
Linux kernel do_brk() proof-of-concept
exploit code
Linux kernel do_brk() proof-of-concept
exploit code
12/02/2003 12:12 PMChristophe Devine (Dec 01 2003)
Re: Linux kernel do_brk()
proof-of-concept exploit code
Re: Linux kernel do_brk()
proof-of-concept exploit code
12/02/2003 02:40 PMCalum (Dec 02 2003)
Linux kernel do_brk(), another
proof-of-concept code for i386
Linux kernel do_brk(), another
proof-of-concept code for i386
12/04/2003 01:17 PMJulien TINNES (Dec 04 2003)
Linux Kernel Vulnerability
Linux Kernel Vulnerability
08/05/2004 01:56 AMDirect and Related Links for 'Linux Kernel
Vulnerability'
“Paul Starzetz has reported a vulnerability in the Linux
kernel, which can be exploited by malicious, local users to disclose
sensitive information in kernel memory….Solution: Grant only
trusted users access to affected systems.”…
Re: Linux kernel mremap vulnerability
Re: Linux kernel mremap vulnerability
01/05/2004 02:50 PMPaul Starzetz (Jan 05 2004)
Linux kernel mremap vulnerability
Linux kernel mremap vulnerability
01/05/2004 02:50 PMPaul Starzetz (Jan 05 2004)
Remote DoS vulnerability in Linux kernel
2.6.x
Remote DoS vulnerability in Linux kernel
2.6.x
06/30/2004 01:09 PMAdam Osuchowski (Jun 30 2004)
"Linux kernel vulnerability behind
Debian attack"
"Linux kernel vulnerability behind
Debian attack"
12/02/2003 10:19 PMLinux Kernel i2c Integer Overflow
Vulnerability
Linux Kernel i2c Integer Overflow
Vulnerability
06/16/2004 07:32 PMShaun Colley (Jun 16 2004)
Re: Linux Kernel i2c Integer Overflow
Vulnerability
Re: Linux Kernel i2c Integer Overflow
Vulnerability
06/17/2004 09:17 PMAlexander Nyberg (Jun 16 2004)
Linux kernel vulnerability behind Debian
attack
Linux kernel vulnerability behind Debian
attack
12/02/2003 10:21 PMA bug in versions of the Linux kernel prior to Version 2.4.23 allows
users on a Linux machine to gain unlimited access privileges,
according to an advisory from developers of the Debian Linux
distribution.
Linux Kernel Floating Point Leak
Vulnerability
Linux Kernel Floating Point Leak
Vulnerability
07/13/2004 10:33 AM“Arun Sharma has reported a vulnerability in the Linux kernel,
which potentially can be exploited by malicious, local users to gain
knowledge of sensitive information….The vulnerability only
affects Linux ia64 kernels.” “Solution: Upgrade to
version 2.4.26 or higher, as it has been reported to fix this
vulnerability. It is also possible to correct the flaw by implementing
applicable patches from your respective Linux vendor.”
[ GLSA 200402-06 ] Linux kernel AMD64
ptrace vulnerability
[ GLSA 200402-06 ] Linux kernel AMD64
ptrace vulnerability
02/17/2004 01:05 PMTim Yamin (Feb 16 2004)
do_brk() vulnerability on SGI Altix
systems
do_brk() vulnerability on SGI Altix
systems
12/03/2003 02:42 PMSGI Security Coordinator (Dec 02 2003)
[ GLSA 200407-12 ] Linux Kernel: Remote
DoS vulnerability with IPTables TCP
Handling
[ GLSA 200407-12 ] Linux Kernel: Remote
DoS vulnerability with IPTables TCP
Handling
07/16/2004 10:15 PMTim Yamin (Jul 14 2004)
[ GLSA 200403-02 ] Linux kernel
do_mremap local privilege escalation
vulnerability
[ GLSA 200403-02 ] Linux kernel
do_mremap local privilege escalation
vulnerability
03/08/2004 11:20 PMTim Yamin (Mar 06 2004)
Linux Kernel ISO9660 File System
Component Buffer Overflow Vulnerability
Linux Kernel ISO9660 File System
Component Buffer Overflow Vulnerability
04/15/2004 09:12 AMNetBSD kernel swapctl(2) vulnerability
NetBSD kernel swapctl(2) vulnerability
06/14/2004 06:02 PMEvgeny Demidov (Jun 11 2004)
[HOTFIX] setsockopt kernel vulnerability
[HOTFIX] setsockopt kernel vulnerability
04/26/2004 01:18 PMnolife (Apr 26 2004)
Layer-7 Packet Classifier for Linux
0.0.2 (Linux Kernel 2.6 Netfilter patch)
Layer-7 Packet Classifier for Linux
0.0.2 (Linux Kernel 2.6 Netfilter patch)
10/31/2003 02:44 AMA layer-7 packet classifier for packet shaping.
Layer-7 Packet Classifier for Linux
0.1.0 (Linux Kernel 2.6 Netfilter patch)
Layer-7 Packet Classifier for Linux
0.1.0 (Linux Kernel 2.6 Netfilter patch)
11/10/2003 11:33 PMA layer-7 packet classifier for packet shaping.
Layer-7 Packet Classifier for Linux
0.4.0 (Linux Kernel 2.6 Netfilter patch)
Layer-7 Packet Classifier for Linux
0.4.0 (Linux Kernel 2.6 Netfilter patch)
12/06/2003 03:55 AMAn application-layer packet classifier for Linux.
McObject’s eXtremeDB - First In-Memory
Database for BlueCat Linux 5.0 and Linux
2.6 Kernel
McObject’s eXtremeDB - First In-Memory
Database for BlueCat Linux 5.0 and Linux
2.6 Kernel
06/22/2004 02:43 AMWith McObject’s release of its eXtremeDB 2.3 in-memory embedded
database for LynuxWorks’ BlueCat Linux 5.0 operating system,
developers of embedded Linux applications for the first time have an
in-memory database system (IMDS) available for LynuxWorks’ powerful
embedded platform, and for the Linux 2.6 kernel on which BlueCat Linux
5.0 is based. [PRWEB Jun 22, 2004]
Samba 3.x + kernel 2.6.x local root
vulnerability
Samba 3.x + kernel 2.6.x local root
vulnerability
02/10/2004 02:57 AMMichal Medvecky (Feb 09 2004)
Re: Samba 3.x + kernel 2.6.x local root
vulnerability
Re: Samba 3.x + kernel 2.6.x local root
vulnerability
02/10/2004 02:57 AMPatrick J. Volkerding (Feb 09 2004)
OpenOffice.org details vulnerability
OpenOffice.org details vulnerability
04/13/2005 11:14 AM OpenOffice.org, an open-source software maker, has confirmed a
buffer overflow issue that could allow for remote attacks.
The problem in its freely distributed productivity applications has
been fixed, the organization said late Tuesday. But no patch has yet
been publicly issued. The flaw, first discovered in late March,
according to
postings on the group's Web
site, is present in OpenOffice Version 1.1.4 and the OpenOffice
Version 2.0 beta release of the applications, as well as in earlier
versions of those products.

News source:
C|Net News.comRead full story...Openwall Linux kernel patch 2.4.30-ow1
(Linux 2.4 branch)
Openwall Linux kernel patch 2.4.30-ow1
(Linux 2.4 branch)
04/08/2005 10:32 AM
The Openwall Linux kernel patch is a collection of security
"hardening" features for the Linux kernel. In addition to the new
features, some versions of the patch contain various security fixes.
The "hardening" features of the patch, while not a complete method of
protection, provide an extra layer of security against the easier ways
to exploit certain classes of vulnerabilities and/or reduce the impact
of those vulnerabilities. The patch can also add a little bit more
privacy to the system by restricting access to parts of /proc so that
users may not see what others are doing.
Changes:
This release was updated to Linux 2.4.30.
Kernel Mode Linux 2.4.31_001 (For Linux
2.4 branch)
Kernel Mode Linux 2.4.31_001 (For Linux
2.4 branch)
06/05/2005 11:23 PM
Kernel Mode Linux is a technology which enables
the execution of user programs in a kernel mode.
In Kernel Mode Linux, user programs can access
kernel address space directly. Unlike kernel
modules, user programs are executed as ordinary
processes (except for their privilege level), so
scheduling and paging are performed as usual.
Although it seems dangerous, the safety of the
kernel can be ensured through such methods as
static type checking, software fault isolation,
and so forth.
License: GNU General Public License (GPL)
Changes:
This version was merged with the 2.4.31 Linux
kernel.
Kernel Mode Linux 2.4.30_001 (For Linux
2.4 branch)
Kernel Mode Linux 2.4.30_001 (For Linux
2.4 branch)
04/05/2005 11:56 AM
Kernel Mode Linux is a technology which enables
the execution of user programs in a kernel mode.
In Kernel Mode Linux, user programs can access
kernel address space directly. Unlike kernel
modules, user programs are executed as ordinary
processes (except for their privilege level), so
scheduling and paging are performed as usual.
Although it seems dangerous, the safety of the
kernel can be ensured through such methods as
static type checking, software fault isolation,
and so forth.
Changes:
This version was merged with the 2.4.30 Linux
kernel.
MDKSA-2003:110 - Updated kernel packages
fix vulnerability
MDKSA-2003:110 - Updated kernel packages
fix vulnerability
12/02/2003 12:32 AMMandrake Linux Security Team (Dec 01 2003)
[RHSA-2003:417-01] Updated kernel
resolves security vulnerability
[RHSA-2003:417-01] Updated kernel
resolves security vulnerability
01/05/2004 02:50 PMbugzilla_at_redhat.com (Jan 05 2004)
Kernel Mode Linux 2.6.0-mm1_001 (For
Linux 2.6-mm)
Kernel Mode Linux 2.6.0-mm1_001 (For
Linux 2.6-mm)
12/26/2003 12:33 PMA factility for executing user processes in kernel mode safely.
Kernel Mode Linux 2.6.7_001 (For Linux
2.6)
Kernel Mode Linux 2.6.7_001 (For Linux
2.6)
06/21/2004 04:21 AMA factility for executing user processes in kernel mode safely.
MOSIX Kernel Patch 1.11.1 for Linux
2.4.26 (Linux 2.4)
MOSIX Kernel Patch 1.11.1 for Linux
2.4.26 (Linux 2.4)
04/21/2004 02:26 PMA cluster management system for Unix.
Kernel Mode Linux 2.4.23_001 (For Linux
2.4)
Kernel Mode Linux 2.4.23_001 (For Linux
2.4)
12/02/2003 01:59 AMA factility for executing user processes in kernel mode safely.
Openwall Linux kernel patch 2.4.26-ow2
(Linux 2.4)
Openwall Linux kernel patch 2.4.26-ow2
(Linux 2.4)
06/19/2004 01:50 PMA security "hardening" patch for the Linux kernel.
Kernel Mode Linux 2.6.0-test9_002 (For
Linux 2.6)
Kernel Mode Linux 2.6.0-test9_002 (For
Linux 2.6)
11/12/2003 01:31 PMA factility for executing user processes in kernel mode safely.
Grok Description matches for [iSEC] Linux kernel do_brk() vulnerability details
GrokA matches for [iSEC] Linux kernel do_brk() vulnerability details
[iSEC] Linux kernel do_brk() vulnerability details