First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 86784
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Thierry Carrez (RETIRED) <koon@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
CAN-2005-0815.patch CAN-2005-0815 fix patch from bk-commits-head patch Lorenzo Hernández García-Hierro 2005-05-04 13:38 0000 3.34 KB Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 86784 depends on: Show dependency tree
Show dependency graph
Bug 86784 blocks:

Additional Comments: (this is where you put emerge --info)







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-03-26 09:25 0000
Fixed in vanilla 2.6.11.6
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.6

Michal Zalewski <lcamtuf@dione.ids.pl> discovers range checking flaws in iso9660 filesystem.
	
CAN-2005-0815 is assigned to this issue.

------- Comment #1 From Joshua Kinard 2005-04-23 22:28:14 0000 -------
mips-sources fixed.

------- Comment #2 From Daniel Drake 2005-04-27 13:46:08 0000 -------
Fixed in gentoo-sources-2.6.11-r6

------- Comment #3 From Daniel Drake 2005-04-29 17:39:32 0000 -------
Fixed in usermode-sources-2.6.11

------- Comment #4 From Lorenzo Hernández García-Hierro 2005-05-04 13:38:45 0000 -------
Created an attachment (id=58067) [edit]
CAN-2005-0815 fix patch from bk-commits-head

Also at http://pearls.tuxedo-es.org/gentoo/kernel/CAN-2005-0815.patch.

I'm going to add it to the patchset for hardened-sources and update the ebuild,
then upload to:
http://pearls.tuxedo-es.org/gentoo/hardened/kernel/

Come on tocharian :)

Cheers,
Lorenzo.

------- Comment #5 From Lorenzo Hernández García-Hierro 2005-05-05 06:04:16 0000 -------
Updated hardened-sources patchset to fix CAN-2005-0815:

http://pearls.tuxedo-es.org/gentoo/hardened/kernel/

Cheers,
Lorenzo.

------- Comment #6 From Daniel Drake 2005-05-10 15:33:08 0000 -------
Fixed in ck-sources-2.6.11-r7

------- Comment #7 From Thierry Carrez (RETIRED) 2005-05-23 04:59:57 0000 -------
This also affects the 2.4 series.

From solar :
grsec-sources-2.4.30 is in the tree as ~arch.

Note for other bumpers of 2.4.x series.
CAN-2004-1056.patch and linux-2.4.28-random-poolsize.patch have never 
been applied to mainline.

------- Comment #8 From Tim Yamin (RETIRED) 2005-08-20 11:59:18 0000 -------
kang: rsbac-sources-2.4 needs fix.

------- Comment #9 From Guillaume Destuynder (RETIRED) 2005-11-14 10:48:58 0000 -------
sorry i didnt catch that bug for some reason:/
but it was fixed by then anyway.
now too :)

------- Comment #10 From Tim Yamin (RETIRED) 2005-11-26 03:04:42 0000 -------
All fixed, closing bug.

First Last Prev Next    No search results available      Search page      Enter new bug