|
Message-ID: <1232869034.333911280865635594.JavaMail.root@zmail01.collab.prod.int.phx2.redhat.com> Date: Tue, 3 Aug 2010 16:00:35 -0400 (EDT) From: Josh Bressers <bressers@...hat.com> To: oss-security@...ts.openwall.com Cc: "Steven M. Christey" <coley@...us.mitre.org> Subject: Re: kernel: [PARISC] led.c - fix potential stack overflow in led_proc_write() Steve, This one will need a 2007 ID. Thanks. -- JB ----- "Moritz Muehlenhoff" <jmm@...til.org> wrote: > On Tue, Aug 03, 2010 at 11:46:58AM +0800, Eugene Teo wrote: > > Ilja reported way back in Nov 2007. A writer to /proc/pdc/led(?) > can > > cause the kernel to consume an unbounded amount of stack, and > result > > in stack corruption. > > > > http://www.spinics.net/lists/linux-parisc/msg02960.html > > > > If you need a CVE name, change the subject to indicate that. We are > > not requesting one as we do not support the PA-RISC architecture in > > our distribution. > > Debian supports hppa. > > Steven, please assign a CVE ID. > > Cheers, > Moritz
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.