[<prev] [next>] [day] [month] [year] [list]
Message-ID: <54DEB0DD.6030305@upv.es>
Date: Sat, 14 Feb 2015 03:20:13 +0100
From: Hector Marco <hecmargi@....es>
To: fulldisclosure@...lists.org, bugs@...uritytracker.com,
bugtraq@...urityfocus.com
Subject: [FD] CVE-2015-1593 - Linux ASLR integer overflow: Reducing stack
entropy by four
Hi,
A bug in Linux ASLR implementation for versions prior to 3.19-rc3 has
been found. The issue is that the stack for processes is not properly
randomized on some 64 bit architectures due to an integer overflow.
Affected systems have reduced the stack entropy of the processes by four.
Details at:
http://hmarco.org/bugs/linux-ASLR-integer-overflow.html
Regards,
Hector Marco.
http://hmarco.org
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/
Powered by blists - more mailing lists