VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-2240
kernel: The do_anonymous_page function in mm/memory.c in th...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2240

Original

The do_anonymous_page function in mm/memory.c in the Linux kernel before 2.6.27.52, 2.6.32.x before 2.6.32.19, 2.6.34.x before 2.6.34.4, and 2.6.35.x before 2.6.35.2 does not properly separate the stack and the heap, which allows context-dependent attackers to execute arbitrary code by writing to the bottom page of a shared memory segment, as demonstrated by a memory-exhaustion attack against the X.Org X server.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-09-03
Source Information Category:
Advisory, Alert
Last Updated:
2010-09-06




Affected Product Tags
cpe:/o:linux:kernel:2.6.27.51 and previous versions
cpe:/o:linux:kernel:2.6.32
cpe:/o:linux:kernel:2.6.32.1
cpe:/o:linux:kernel:2.6.32.10
cpe:/o:linux:kernel:2.6.32.11
cpe:/o:linux:kernel:2.6.32.12
cpe:/o:linux:kernel:2.6.32.13
cpe:/o:linux:kernel:2.6.32.14
cpe:/o:linux:kernel:2.6.32.15
cpe:/o:linux:kernel:2.6.32.16
cpe:/o:linux:kernel:2.6.32.17
cpe:/o:linux:kernel:2.6.32.18
cpe:/o:linux:kernel:2.6.32.2
cpe:/o:linux:kernel:2.6.32.3
cpe:/o:linux:kernel:2.6.32.4
cpe:/o:linux:kernel:2.6.32.5
cpe:/o:linux:kernel:2.6.32.6
cpe:/o:linux:kernel:2.6.32.7
cpe:/o:linux:kernel:2.6.32.8
cpe:/o:linux:kernel:2.6.32.9
cpe:/o:linux:kernel:2.6.34.1
cpe:/o:linux:kernel:2.6.34.2
cpe:/o:linux:kernel:2.6.34.3
cpe:/o:linux:kernel:2.6.35.1
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

X Local [?]
Adjacent Network [?]
Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
Medium [?]
X Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

Alternatives




References
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=606611




CONFIRM http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.35.2




CONFIRM http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.34.4




CONFIRM http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32.19




CONFIRM http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.52




CONFIRM http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=320b2b8de12698082609ebbc1a17165727f4c893




MISC http://www.invisiblethingslab.com/resources/misc-2010/xorg-large-memory-attacks.pdf




REDHAT RHSA-2010:0661




SECTRACK 1024344




Vulnerability Type Code Injection (CWE-94)





Copyright © 2010 JPCERT/CC All Rights Reserved.