Bug 13381 - Mageia kernel is vulnerable to CVE-2014-0196: raw mode PTY local echo race condition
Summary: Mageia kernel is vulnerable to CVE-2014-0196: raw mode PTY local echo race co...
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 4
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Thomas Backlund
QA Contact: Sec team
URL:
Whiteboard: MGA3TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2014-05-15 13:54 CEST by Pavel Kreuzt
Modified: 2014-05-28 15:48 CEST (History)
0 users

See Also:
Source RPM: kernel-3.12.18-1.mga4.src.rpm
CVE:
Status comment:


Attachments

Description Pavel Kreuzt 2014-05-15 13:54:03 CEST
Description of problem: Our kernel is still vulnerable to this issue, described here http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0196
I tested 2 different POC, a privilege scalation one that did't worked and a DOS that hanged the computer.


Version-Release number of selected component (if applicable):


How reproducible:


Steps to Reproduce:
1.
2.
3.


Reproducible: 

Steps to Reproduce:
David Walser 2014-05-15 14:09:41 CEST

Assignee: bugsquad => tmb
Whiteboard: (none) => MGA3TOO

Comment 1 David Walser 2014-05-28 15:48:19 CEST
I guess this is fixed now.

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.