Linux Kernel x86_64 ptrace Denial Of Service Vulnerability
BID:29086
Info
Linux Kernel x86_64 ptrace Denial Of Service Vulnerability
| Bugtraq ID: | 29086 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-1615 |
| Remote: | No |
| Local: | Yes |
| Published: | May 07 2008 12:00AM |
| Updated: | Mar 19 2015 09:45AM |
| Credit: | Jan Kratochvil |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 lpia Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 10 SP2 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise SDK 10 SP2 SuSE SUSE Linux Enterprise SDK 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SP2 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE SUSE Linux Enterprise 10 SP2 DEBUGINFO SuSE SUSE Linux Enterprise 10 SP1 DEBUGINFO SuSE openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 RedHat Enterprise MRG v1 for Red Hat Enterprise Linux version 5 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 4 RedHat Desktop 4.0 Red Hat Fedora 7 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux 5 Server Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Linux kernel 2.6.18 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Voice Portal 4.1 Avaya Voice Portal 4.0 Avaya Voice Portal 3.0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 3.1 Avaya Message Networking MN 3.1 Avaya Message Networking 3.1 Avaya Intuity AUDIX LX 2.0 Avaya EMMC 1.021 Avaya EMMC 1.017 Avaya Communication Manager 5.0 Avaya Communication Manager 4.0 Avaya Communication Manager 3.1 Avaya Communication Manager 3.0 Avaya Aura SIP Enablement Services 3.1.1 Avaya Aura SIP Enablement Services 5.0 Avaya Aura SIP Enablement Services 3.1 Avaya Aura SIP Enablement Services 3.0 Avaya Aura Application Enablement Services 4.2 |
| Not Vulnerable: | |
Discussion
Linux Kernel x86_64 ptrace Denial Of Service Vulnerability
The Linux kernel is prone to a denial-of-service vulnerability when process traces are performed on 64-bit computers.
Local attackers can leverage the issue to crash the kernel and deny service to legitimate users.
The Linux kernel is prone to a denial-of-service vulnerability when process traces are performed on 64-bit computers.
Local attackers can leverage the issue to crash the kernel and deny service to legitimate users.
Exploit / POC
Linux Kernel x86_64 ptrace Denial Of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Linux Kernel x86_64 ptrace Denial Of Service Vulnerability
Solution:
Fixes are available. Please see the references for more information.
MandrakeSoft Corporate Server 4.0
MandrakeSoft Corporate Server 4.0 x86_64
Solution:
Fixes are available. Please see the references for more information.
MandrakeSoft Corporate Server 4.0
-
Mandriva kernel-2.6.12.36mdk-1-1mdk.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva kernel-BOOT-2.6.12.36mdk-1-1mdk.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva kernel-doc-2.6.12.36mdk-1-1mdk.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva kernel-i586-up-1GB-2.6.12.36mdk-1-1mdk.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva kernel-i686-up-4GB-2.6.12.36mdk-1-1mdk.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva kernel-smp-2.6.12.36mdk-1-1mdk.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva kernel-source-2.6.12.36mdk-1-1mdk.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva kernel-source-stripped-2.6.12.36mdk-1-1mdk.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva kernel-xbox-2.6.12.36mdk-1-1mdk.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva kernel-xen0-2.6.12.36mdk-1-1mdk.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva kernel-xenU-2.6.12.36mdk-1-1mdk.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0 x86_64
-
Mandriva kernel-2.6.12.36mdk-1-1mdk.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva kernel-BOOT-2.6.12.36mdk-1-1mdk.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva kernel-doc-2.6.12.36mdk-1-1mdk.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva kernel-smp-2.6.12.36mdk-1-1mdk.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva kernel-source-2.6.12.36mdk-1-1mdk.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva kernel-source-stripped-2.6.12.36mdk-1-1mdk.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva kernel-xen0-2.6.12.36mdk-1-1mdk.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva kernel-xenU-2.6.12.36mdk-1-1mdk.x86_64.rpm
http://www.mandriva.com/en/download/
References
Linux Kernel x86_64 ptrace Denial Of Service Vulnerability
References:
References:
- Bugzilla Bug 431430: CVE-2008-1615 kernel: ptrace: Unprivileged crash on x86_64 (Red Hat)
- Linux Homepage (Linux)
- Advisory: RHSA-2008:0585-24 Important: kernel security and bug fix update (Red Hat)
- ASA-2008-225 kernel security and bug fix update (RHSA-2008-0237) (Avaya)
- MDVSA-2008:167 - kernel (Mandriva)
- RHSA-2008:0237-10 kernel security and bug fix update (Red Hat)
- RHSA-2008:0275-7 kernel security and bug fix update (Red Hat)
- USN-625-1: Linux kernel vulnerabilities (Ubuntu)