>> Linux Kernel Local Denial of Service and Security Bypass Issues
Title : Linux Kernel Local Denial of Service and Security Bypass Issues VUPEN ID : VUPEN/ADV-2005-2039 CVE ID : CVE-2005-3119 - CVE-2005-3179 - CVE-2005-3180 - CVE-2005-3181
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2005-10-11
Technical Description
Multiple vulnerabilities were identified in Linux Kernel, which could be exploited by local attackers to cause a denial of service or bypass certain security restrictions.
The first issue is due to a memory leak error in "/security/keys/request_key_auth.c", which could be exploited by malicious users to cause a denial of service.
The second vulnerability is due to a memory leak error in "/fs/namei.c" when the CONFIG_AUDITSYSCALL option is enabled, which could be exploited by malicious users to cause a denial of service.
The third flaw is due to an error in the file "drivers/char/drm/drm_stub.c" that does not properly validate "debug" sysfs permissions, which could be exploited by local attackers to bypass certain security restrictions and enable drm debugging.
The fourth problem resides in the orinoco wireless driver that fails to pad certain data packets, which could be exploited to disclose portions of the memory.