CERT-In Vulnerability Note
CIVN-2008-0195
Linux Kernel 'parisc_show_stack ' Local Denial of Service Vulnerability
Original Issue Date:December 22, 2008
Severity Rating: MEDIUM
Systems Affected
- Linux Kernel Versions prior to 2.6.28-rc7
Overview
A vulnerability was reported in the Linux kernel which allows a local attacker to cause a denial of service condition.
Description
This vulnerability caused due to an error in the parisc_show_stack tion in the 'arch/parisc/kernel /traps.c source file. The issue occurs when unwinding a stack containing user space memory addresses.
A local attacker can change the stack of process, to force parisc_show_stack to use invalid memory addresses, which cause a denial of service, denying service to legitimate users.
Solution
Upgrade to Version 2.6.28-rc7.
http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.28-rc7
Vendor Information
Kernel.org
http://www.kernel.org/
References
Kernel.org
http://www.kernel.org/
Juniper Networks
http://www.juniper.net/security/auto/vulnerabilities/vuln32636.html
Global Security Mag
http://www.globalsecuritymag.com/Vigil-nce-Linux-kernel-denial-of,20081212,6557
Secunia
http://secunia.com/Advisories/32933/
SecurityFocus
http://www.securityfocus.com/bid/32261
CVE Name
CVE-2008-5395
CWE Name
CWE-119
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|