Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 86784 - Kernel: iso9660 range checking flaws (CAN-2005-0815)
Summary: Kernel: iso9660 range checking flaws (CAN-2005-0815)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All All
: High normal (vote)
Assignee: Gentoo Security
URL: http://marc.theaimsgroup.com/?l=bugtr...
Whiteboard: [linux < 2.4.30] [linux >= 2.6 < 2.6....
Keywords:
Depends on:
Blocks:
 
Reported: 2005-03-26 09:25 UTC by Thierry Carrez (RETIRED)
Modified: 2009-05-03 15:05 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
CAN-2005-0815 fix patch from bk-commits-head (CAN-2005-0815.patch,3.34 KB, patch)
2005-05-04 13:38 UTC, Lorenzo Hernández García-Hierro
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Thierry Carrez (RETIRED) gentoo-dev 2005-03-26 09:25:22 UTC
Fixed in vanilla 2.6.11.6
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.6

Michal Zalewski <lcamtuf@dione.ids.pl> discovers range checking flaws in iso9660 filesystem.
	
CAN-2005-0815 is assigned to this issue.
Comment 1 Joshua Kinard gentoo-dev 2005-04-23 22:28:14 UTC
mips-sources fixed.
Comment 2 Daniel Drake (RETIRED) gentoo-dev 2005-04-27 13:46:08 UTC
Fixed in gentoo-sources-2.6.11-r6
Comment 3 Daniel Drake (RETIRED) gentoo-dev 2005-04-29 17:39:32 UTC
Fixed in usermode-sources-2.6.11
Comment 4 Lorenzo Hernández García-Hierro 2005-05-04 13:38:45 UTC
Created attachment 58067 [details, diff]
CAN-2005-0815 fix patch from bk-commits-head

Also at http://pearls.tuxedo-es.org/gentoo/kernel/CAN-2005-0815.patch.

I'm going to add it to the patchset for hardened-sources and update the ebuild,
then upload to:
http://pearls.tuxedo-es.org/gentoo/hardened/kernel/

Come on tocharian :)

Cheers,
Lorenzo.
Comment 5 Lorenzo Hernández García-Hierro 2005-05-05 06:04:16 UTC
Updated hardened-sources patchset to fix CAN-2005-0815:

http://pearls.tuxedo-es.org/gentoo/hardened/kernel/

Cheers,
Lorenzo.
Comment 6 Daniel Drake (RETIRED) gentoo-dev 2005-05-10 15:33:08 UTC
Fixed in ck-sources-2.6.11-r7
Comment 7 Thierry Carrez (RETIRED) gentoo-dev 2005-05-23 04:59:57 UTC
This also affects the 2.4 series.

From solar :
grsec-sources-2.4.30 is in the tree as ~arch.

Note for other bumpers of 2.4.x series.
CAN-2004-1056.patch and linux-2.4.28-random-poolsize.patch have never 
been applied to mainline.
Comment 8 Tim Yamin (RETIRED) gentoo-dev 2005-08-20 11:59:18 UTC
kang: rsbac-sources-2.4 needs fix.
Comment 9 Guillaume Destuynder (RETIRED) gentoo-dev 2005-11-14 10:48:58 UTC
sorry i didnt catch that bug for some reason:/
but it was fixed by then anyway.
now too :)
Comment 10 Tim Yamin (RETIRED) gentoo-dev 2005-11-26 03:04:42 UTC
All fixed, closing bug.