Bug 82141 - Kernel signed types issues (CAN-2005-{0529,0530,0531,0532})
Bug#: 82141 Product:  Gentoo Security Version: unspecified Platform: All
OS/Version: All Status: RESOLVED Severity: major Priority: P2
Resolution: FIXED Assigned To: security@gentoo.org Reported By: jaervosz@gentoo.org
Component: Kernel
URL:  http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html
Summary: Kernel signed types issues (CAN-2005-{0529,0530,0531,0532})
Keywords:  
Status Whiteboard: [linux >=2.6 < 2.6.11]
Opened: 2005-02-15 11:30 0000
Description:   Opened: 2005-02-15 11:30 0000
For full description see the link.

------- Comment #1 From Thierry Carrez (RETIRED) 2005-02-16 06:16:38 0000 -------
*** Bug 82221 has been marked as a duplicate of this bug. ***

------- Comment #2 From Jakub Moc (RETIRED) 2005-02-17 01:01:11 0000 -------
Hmm - some more vulnerabilities... :-(

http://secunia.com/advisories/14295/

- nls_ascii.c buffer overflow (potential crash kernel exploit)
- error in netfilter (potential crash kernel exploit or bypass of firewall rules)

------- Comment #3 From Sune Kloppenborg Jeppesen 2005-02-28 13:21:57 0000 -------
CANs assigned:
CAN-2005-0529
CAN-2005-0530
CAN-2005-0531
CAN-2005-0532

------- Comment #4 From Thierry Carrez (RETIRED) 2005-03-16 02:25:32 0000 -------
From Ubuntu's latest:

Georgi Guninski discovered a buffer overflow in the ATM driver. The
atm_get_addr() function does not validate its arguments sufficiently,
which could allow a local attacker to overwrite large portions of
kernel memory by supplying a negative length argument. This could
eventually lead to arbitrary code execution. (CAN-2005-0531)

Georgi Guninski also discovered three other integer comparison
problems in the TTY layer, in the /proc interface and the ReiserFS
driver. However, the previous Ubuntu security update (kernel version
2.6.8.1-16.11) already contained a patch which checks the arguments to
these functions at a higher level and thus prevents these flaws from
being exploited. (CAN-2005-0529, CAN-2005-0530, CAN-2005-0532)

------- Comment #5 From Thierry Carrez (RETIRED) 2005-03-16 02:28:57 0000 -------
*** Bug 80107 has been marked as a duplicate of this bug. ***

------- Comment #6 From Thierry Carrez (RETIRED) 2005-03-16 03:16:50 0000 -------
Mass-Ccing kern-sec@gentoo.org to make sure Kernel Security guys know about all
of these...

------- Comment #7 From Daniel Drake 2005-03-16 05:57:57 0000 -------
gentoo-dev-sources unaffected

------- Comment #8 From Tim Yamin (RETIRED) 2005-04-06 13:56:52 0000 -------
Created an attachment (id=55516) [details]
Patch

------- Comment #9 From Tim Yamin (RETIRED) 2005-04-06 13:58:03 0000 -------
Everything seems to have been patched or upgraded to 2.6.11; mips-sources
branches remain that still need patching so CCing Kumba.

------- Comment #10 From Joshua Kinard 2005-04-23 22:25:53 0000 -------
mips-sources fixed.

------- Comment #11 From Robert Paskowitz (RETIRED) 2005-05-17 16:29:44 0000 -------
KISS says all done: http://kiss.gentoo.org/dev/viewBug.php?BugID=82141

------- Comment #12 From Tim Yamin (RETIRED) 2005-05-27 11:38:44 0000 -------
All fixed, closing bug.