[kernel] r4859 - patch-tracking

Dann Frazier dannf at costa.debian.org
Mon Nov 21 17:56:07 UTC 2005


Author: dannf
Date: Mon Nov 21 17:56:06 2005
New Revision: 4859

Added:
   patch-tracking/CAN-2004-1068
      - copied, changed from r4853, patch-tracking/00boilerplate
Log:
an older issue; already fixed in sarge but not woody

Copied: patch-tracking/CAN-2004-1068 (from r4853, patch-tracking/00boilerplate)
==============================================================================
--- patch-tracking/00boilerplate	(original)
+++ patch-tracking/CAN-2004-1068	Mon Nov 21 17:56:06 2005
@@ -1,13 +1,30 @@
-Candidate: 
+Candidate: CAN-2004-1068
 References: 
+ BUGTRAQ:20041119 Addendum, recent Linux <= 2.4.27 vulnerabilities
+ URL:http://www.securityfocus.com/archive/1/381689
+ FEDORA:FLSA:2336
+ URL:https://bugzilla.fedora.us/show_bug.cgi?id=2336
+ MANDRAKE:MDKSA-2005:022
+ URL:http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022
+ REDHAT:RHSA-2004:537
+ URL:http://www.redhat.com/support/errata/RHSA-2004-537.html
+ BUGTRAQ:20041214 [USN-38-1] Linux kernel vulnerabilities
+ URL:http://marc.theaimsgroup.com/?l=bugtraq&m=110306397320336&w=2
+ BID:11715
+ URL:http://www.securityfocus.com/bid/11715
+ XF:linux-afunix-race-condition(18230)
+ URL:http://xforce.iss.net/xforce/xfdb/18230
 Description: 
+ A "missing serialization" error in the unix_dgram_recvmsg function in Linux
+ 2.4.27 and earlier, and 2.6.x up to 2.6.9, allows local users to gain
+ privileges via a race condition.
 Notes: 
 Bugs: 
-upstream: 
-2.6.14: 
-2.6.8-sarge-security: 
-2.4.27-sarge-security: 
-2.6.8: 
+upstream: released (2.4.27, 2.6.9)
+2.6.14: N/A
+2.6.8-sarge-security: released (2.6.8-11)
+2.4.27-sarge-security: released (2.4.27-7)
+2.6.8: released (2.6.8-11)
 2.4.19-woody-security: 
 2.4.18-woody-security: 
 2.4.17-woody-security: 



More information about the Kernel-svn-changes mailing list