[Bug 173849] [CVE-2007-5500] [linux-source] possible DoS in ptrace attach logic

hk47 bugtracker at slideomania.com
Tue Dec 4 09:14:52 UTC 2007


Public bug reported:

Binary package hint: linux-source

References:
[1] CVE-2007-5500 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5500)
[2] SUSE-SA:2007:063

Quoting [1]:
"The wait_task_stopped function in the Linux kernel before 2.6.23.8 checks a TASK_TRACED bit instead of an exit_state value, which allows local users to cause a denial of service (machine crash) via unspecified vectors. NOTE: some of these details are obtained from third party information."

Quoting [2]:
"A buggy condition in the ptrace attach logic can be used by local attackers to hang the machine."

** Affects: linux-meta (Ubuntu)
     Importance: Undecided
         Status: New

** Visibility changed to: Public

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2007-5500

-- 
[CVE-2007-5500] [linux-source] possible DoS in ptrace attach logic
https://bugs.launchpad.net/bugs/173849
You received this bug notification because you are a member of Kernel
Bugs, which is a bug contact for linux-meta in ubuntu.




More information about the kernel-bugs mailing list