Summary
Ubuntu Update for Linux kernel vulnerabilities USN-577-1
Solution
Please Install the Updated Packages.
Insight
Wojciech Purczynski discovered that the vmsplice system call did not properly perform verification of user-memory pointers. A local attacker could exploit this to overwrite arbitrary kernel memory and gain root privileges. (CVE-2008-0600)
Affected
linux-source-2.6.17/20/22 vulnerability on Ubuntu 6.10 , Ubuntu 7.04 ,
Ubuntu 7.10
Severity
Classification
-
CVE CVE-2008-0600 -
CVSS Base Score: 7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities