On Mon, May 18, 2009 at 01:28:56PM -0400, Michael S. Gilbert wrote:
> Package: linux-2.6
> Version: 2.6.26-15lenny2
> Severity: important
> Tags: security
> 
> Hi,
> 
> The following CVE (Common Vulnerabilities & Exposures) id was
> published for linux-2.6.
> 
> CVE-2009-0787[0]:
> | The ecryptfs_write_metadata_to_contents function in the eCryptfs
> | functionality in the Linux kernel 2.6.28 before 2.6.28.9 uses an
> | incorrect size when writing kernel memory to an eCryptfs file header,
> | which triggers an out-of-bounds read and allows local users to obtain
> | portions of kernel memory.
> 
> If you fix the vulnerability please also make sure to include the
> CVE id in your changelog entry.
> 
> For further information see:
> 
> [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0787
>     http://security-tracker.debian.net/tracker/CVE-2009-0787

This issue supposedly only affected 2.6.28 - do you have information
to the contrary?

-- 
dann frazier




-- 
To UNSUBSCRIBE, email to debian-kernel-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to