> -------------------------------------------------------------------------- > Debian Security Advisory DSA 444-1 [EMAIL PROTECTED] > http://www.debian.org/security/ Martin Schulze > February 20th, 2004 http://www.debian.org/security/faq > -------------------------------------------------------------------------- > > Package : kernel-image-2.4.17-ia64 > Vulnerability : missing function return value check > Problem-Type : local > Debian-specific: no > CVE ID : CAN-2004-0077 > > Paul Starzetz and Wojciech Purczynski of isec.pl discovered a critical > security vulnerability in the memory management code of Linux inside > the mremap(2) system call. Due to missing function return value check > of internal functions a local attacker can gain root privileges.
This time I haven't played my role in this spectacle. Full credits go to Paul. Cheers, wp -- Wojciech Purczynski iSEC Security Research http://isec.pl/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
