[kernel-sec-discuss] r1526 - active

Michael Gilbert gilbert-guest at alioth.debian.org
Mon Oct 19 21:50:13 UTC 2009


Author: gilbert-guest
Date: 2009-10-19 21:50:13 +0000 (Mon, 19 Oct 2009)
New Revision: 1526

Added:
   active/CVE-2004-2135
   active/CVE-2004-2136
Log:
very old issues that are tracked in the secure-testing tracker, but not kernel-sec

Added: active/CVE-2004-2135
===================================================================
--- active/CVE-2004-2135	                        (rev 0)
+++ active/CVE-2004-2135	2009-10-19 21:50:13 UTC (rev 1526)
@@ -0,0 +1,17 @@
+Candidate: CVE-2004-2135
+Description:
+ cryptoloop on Linux kernel 2.6.x, when used on certain file systems with a block 
+ size 1024 or greater, has certain "IV computation" weaknesses that allow watermarked 
+ files to be detected without decryption.
+References:
+ http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2135
+ http://marc.theaimsgroup.com/?l=linux-kernel&m=107719798631935&w=2
+ http://mareichelt.de/pub/notmine/diskenc.pdf
+ http://www.securiteam.com/exploits/5UP0P1PFPM.html
+Notes:
+Bugs:
+upstream:
+linux-2.6:
+2.6.18-etch-security:
+2.6.24-etch-security:
+2.6.26-lenny-security:

Added: active/CVE-2004-2136
===================================================================
--- active/CVE-2004-2136	                        (rev 0)
+++ active/CVE-2004-2136	2009-10-19 21:50:13 UTC (rev 1526)
@@ -0,0 +1,17 @@
+Candidate: CVE-2004-2136
+Description:
+ dm-crypt on Linux kernel 2.6.x, when used on certain file systems with a block size 
+ 1024 or greater, has certain "IV computation" weaknesses that allow watermarked
+ files to be detected without decryption.
+References:
+ http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2136
+ http://marc.theaimsgroup.com/?l=linux-kernel&m=107719798631935&w=2
+ http://mareichelt.de/pub/notmine/diskenc.pdf
+ http://www.securiteam.com/exploits/5UP0P1PFPM.html
+Notes:
+Bugs:
+upstream:
+linux-2.6:
+2.6.18-etch-security:
+2.6.24-etch-security:
+2.6.26-lenny-security:




More information about the kernel-sec-discuss mailing list