Bug 13381

Summary: Mageia kernel is vulnerable to CVE-2014-0196: raw mode PTY local echo race condition
Product: Mageia Reporter: Pavel Kreuzt <pkreuzt>
Component: SecurityAssignee: Thomas Backlund <tmb>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: normal    
Priority: Normal    
Version: 4   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: MGA3TOO
Source RPM: kernel-3.12.18-1.mga4.src.rpm CVE:
Status comment:

Description Pavel Kreuzt 2014-05-15 13:54:03 CEST
Description of problem: Our kernel is still vulnerable to this issue, described here http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0196
I tested 2 different POC, a privilege scalation one that did't worked and a DOS that hanged the computer.


Version-Release number of selected component (if applicable):


How reproducible:


Steps to Reproduce:
1.
2.
3.


Reproducible: 

Steps to Reproduce:
David Walser 2014-05-15 14:09:41 CEST

Assignee: bugsquad => tmb
Whiteboard: (none) => MGA3TOO

Comment 1 David Walser 2014-05-28 15:48:19 CEST
I guess this is fixed now.

Status: NEW => RESOLVED
Resolution: (none) => FIXED