Matt Mackall
5a021e9ffd
random: fix bound check ordering (CVE-2007-3105)
...
If root raised the default wakeup threshold over the size of the
output pool, the pool transfer function could overflow the stack with
RNG bytes, causing a DoS or potential privilege escalation.
(Bug reported by the PaX Team <pageexec@freemail.hu>)
Cc: Theodore Tso <tytso@mit.edu>
Cc: Willy Tarreau <w@1wt.eu>
Signed-off-by: Matt Mackall <mpm@selenic.com>
Signed-off-by: Chris Wright <chrisw@sous-sol.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2007-07-19 14:21:04 -07:00
..
2007-07-10 08:03:34 +02:00
2007-07-19 10:04:42 -07:00
2007-07-17 16:18:00 -04:00
2007-07-18 02:13:42 -07:00
2007-07-16 09:05:40 -07:00
2007-07-19 10:04:42 -07:00
2007-07-19 10:04:53 -07:00
2007-07-11 06:53:45 +02:00
2007-07-16 08:52:45 +02:00
2007-07-19 14:21:04 -07:00
2007-07-11 16:02:10 -07:00
2007-07-16 09:05:40 -07:00
2007-07-13 01:29:51 -04:00
2007-07-16 09:05:40 -07:00
2007-07-16 09:05:45 -07:00
2007-07-19 10:04:57 -07:00
2007-07-18 23:53:28 +02:00
2007-07-16 09:05:42 -07:00
2007-07-12 16:34:30 -07:00
2007-07-17 10:23:04 -07:00
2007-07-17 10:23:15 -07:00
2007-07-19 10:22:44 -07:00
2007-07-17 10:23:02 -07:00
2007-07-19 10:04:50 -07:00
2007-07-19 10:04:50 -07:00
2007-07-19 10:04:50 -07:00
2007-07-16 12:05:51 +03:00
2007-07-19 10:04:52 -07:00
2007-07-19 10:04:50 -07:00
2007-07-19 10:04:50 -07:00
2007-07-19 10:04:50 -07:00
2007-07-17 10:23:06 -07:00
2007-07-19 10:04:50 -07:00
2007-07-19 10:04:50 -07:00
2007-07-19 10:04:50 -07:00
2007-07-18 16:59:17 +03:00
2007-07-19 10:23:21 -07:00
2007-07-19 10:04:50 -07:00
2007-07-18 08:38:22 -07:00
2007-07-19 10:04:50 -07:00
2007-07-19 10:04:50 -07:00
2007-07-18 15:49:49 -07:00
2007-07-19 10:04:50 -07:00
2007-07-15 16:56:12 -07:00
2007-07-19 10:04:50 -07:00
2007-07-19 10:04:52 -07:00
2007-07-19 10:04:50 -07:00
2007-07-19 10:04:50 -07:00
2007-07-19 10:04:50 -07:00
2007-07-19 10:04:50 -07:00
2007-07-19 10:04:50 -07:00
2007-07-19 10:04:50 -07:00
2007-07-17 10:23:05 -07:00
2007-07-18 08:38:22 -07:00
2007-07-19 10:04:50 -07:00
2007-07-18 15:57:16 -07:00
2007-07-19 10:04:50 -07:00
2007-07-19 10:04:50 -07:00
2007-07-19 10:04:50 -07:00
2007-07-18 08:47:45 -07:00
2007-07-11 16:09:09 -07:00
2007-07-19 10:04:52 -07:00
2007-07-19 10:04:52 -07:00