<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>88740</bug_id>
          
          <creation_ts>2005-04-11 09:07 0000</creation_ts>
          <short_desc>Kernel: sysfs_write_file() integer overflow (CAN-2005-0867)</short_desc>
          <delta_ts>2009-05-03 14:31:01 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Kernel</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>[linux &gt;=2.6 &lt; 2.6.11]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>koon@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>kern-sec@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-04-11 09:07:02 0000</bug_when>
            <thetext>From Ubuntu&apos;s latest:

Alexander Nyberg discovered an integer overflow in the sysfs_write_file() function. A local attacker could exploit this to crash the kernel or possibly even execute arbitrary code with root privileges by writing to an user-writable file in /sys under certain low-memory conditions. However, there are very few cases where a user-writeable sysfs file actually exists. (CAN-2005-0867)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2005-04-15 15:00:14 0000</bug_when>
            <thetext>Created an attachment (id=56386)
Patch
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kumba@gentoo.org</who>
            <bug_when>2005-04-23 22:29:40 0000</bug_when>
            <thetext>mips-sources fixed.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dsd@gentoo.org</who>
            <bug_when>2005-04-27 13:46:49 0000</bug_when>
            <thetext>gentoo-sources-2.6 unaffected</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>r2d2@gentoo.org</who>
            <bug_when>2005-05-17 16:41:14 0000</bug_when>
            <thetext>Should be all fixed. http://kiss.gentoo.org/dev/viewBug.php?BugID=88740</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2005-05-27 11:41:21 0000</bug_when>
            <thetext>All fixed, closing bug.</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>56386</attachid>
            <date>2005-04-15 15:00 0000</date>
            <desc>Patch</desc>
            <filename>88740.patch</filename>
            <type>text/plain</type>
            <data encoding="base64">LS0tIDEuMjIvZnMvc3lzZnMvZmlsZS5jCTIwMDUtMDQtMTUgMTQ6NTg6NDQgLTA3OjAwCisrKyAx
LjIzL2ZzL3N5c2ZzL2ZpbGUuYwkyMDA1LTA0LTE1IDE0OjU4OjQ0IC0wNzowMApAQCAtMjMxLDE1
ICsyMzEsMTYgQEAKIHN5c2ZzX3dyaXRlX2ZpbGUoc3RydWN0IGZpbGUgKmZpbGUsIGNvbnN0IGNo
YXIgX191c2VyICpidWYsIHNpemVfdCBjb3VudCwgbG9mZl90ICpwcG9zKQogewogCXN0cnVjdCBz
eXNmc19idWZmZXIgKiBidWZmZXIgPSBmaWxlLT5wcml2YXRlX2RhdGE7CisJc3NpemVfdCBsZW47
CiAKIAlkb3duKCZidWZmZXItPnNlbSk7Ci0JY291bnQgPSBmaWxsX3dyaXRlX2J1ZmZlcihidWZm
ZXIsYnVmLGNvdW50KTsKLQlpZiAoY291bnQgPiAwKQotCQljb3VudCA9IGZsdXNoX3dyaXRlX2J1
ZmZlcihmaWxlLT5mX2RlbnRyeSxidWZmZXIsY291bnQpOwotCWlmIChjb3VudCA+IDApCi0JCSpw
cG9zICs9IGNvdW50OworCWxlbiA9IGZpbGxfd3JpdGVfYnVmZmVyKGJ1ZmZlciwgYnVmLCBjb3Vu
dCk7CisJaWYgKGxlbiA+IDApCisJCWxlbiA9IGZsdXNoX3dyaXRlX2J1ZmZlcihmaWxlLT5mX2Rl
bnRyeSwgYnVmZmVyLCBsZW4pOworCWlmIChsZW4gPiAwKQorCQkqcHBvcyArPSBsZW47CiAJdXAo
JmJ1ZmZlci0+c2VtKTsKLQlyZXR1cm4gY291bnQ7CisJcmV0dXJuIGxlbjsKIH0KIAogc3RhdGlj
IGludCBjaGVja19wZXJtKHN0cnVjdCBpbm9kZSAqIGlub2RlLCBzdHJ1Y3QgZmlsZSAqIGZpbGUp
Cg==
</data>        

          </attachment>
    </bug>

</bugzilla>