CVE-2010-2492
Priority
Low
Description
Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c
in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow
local users to gain privileges or cause a denial of service (system crash)
via unspecified vectors.
Ubuntu-Description
ecryptfs hashing bug
References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2492
http://www.ubuntu.com/usn/usn-966-1
Assigned-to
smb
Package
Source:
linux-source-2.6.15
(
LP
Ubuntu
Debian
)
Upstream:
not-affected
Ubuntu 8.04 LTS (Hardy Heron):
DNE
Ubuntu 10.04 LTS (Lucid Lynx):
DNE
Package
Source:
linux
(
LP
Ubuntu
Debian
)
Upstream:
pending
Ubuntu 8.04 LTS (Hardy Heron)
:
released
(2.6.24-28.73)
Ubuntu 10.04 LTS (Lucid Lynx)
:
released
(2.6.32-24.39)
Patches:
Hardy:
http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2492/patches/hardy/linux/0001-ecryptfs-Bugfix-for-error-related-to-ecryptfs_hash_buc.txt
Jaunty:
http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2492/patches/jaunty/linux/0001-ecryptfs-Bugfix-for-error-related-to-ecryptfs_hash_buc.txt
Karmic:
http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2492/patches/karmic/linux/0001-ecryptfs-Bugfix-for-error-related-to-ecryptfs_hash_buc.txt
Lucid:
http://chinstrap.ubuntu.com/~smb/CVEs/CVE-2010-2492/patches/lucid/linux/0001-ecryptfs-Bugfix-for-error-related-to-ecryptfs_hash_buc.txt
More Information
Mitre
NVD
Launchpad
Debian
Updated
: 2012-06-01 15:21:09 UTC (commit
5347
)