[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#529326: linux-2.6: CVE-2009-0787 information disclosure in ecryptfs



Package: linux-2.6
Version: 2.6.26-15lenny2
Severity: important
Tags: security

Hi,

The following CVE (Common Vulnerabilities & Exposures) id was
published for linux-2.6.

CVE-2009-0787[0]:
| The ecryptfs_write_metadata_to_contents function in the eCryptfs
| functionality in the Linux kernel 2.6.28 before 2.6.28.9 uses an
| incorrect size when writing kernel memory to an eCryptfs file header,
| which triggers an out-of-bounds read and allows local users to obtain
| portions of kernel memory.

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0787
    http://security-tracker.debian.net/tracker/CVE-2009-0787



Reply to: