Activity log for bug #706149

Date Who What changed Old value New value Message
2011-01-22 00:44:30 Brad Figg bug added bug
2011-01-22 00:44:45 Brad Figg description The USB subsystem in the Linux kernel before 2.6.36-rc5 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to TIOCGICOUNT ioctl calls, and the (1) mos7720_ioctl function in drivers/usb/serial/mos7720.c and (2) mos7840_ioctl function in drivers/usb/serial/mos7840.c. The USB subsystem in the Linux kernel before 2.6.36-rc5 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to TIOCGICOUNT ioctl calls, and the (1) mos7720_ioctl function in drivers/usb/serial/mos7720.c and (2) mos7840_ioctl function in drivers/usb/serial/mos7840.c.
2011-01-22 00:45:15 Brad Figg description The USB subsystem in the Linux kernel before 2.6.36-rc5 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to TIOCGICOUNT ioctl calls, and the (1) mos7720_ioctl function in drivers/usb/serial/mos7720.c and (2) mos7840_ioctl function in drivers/usb/serial/mos7840.c. The USB subsystem in the Linux kernel before 2.6.36-rc5 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to TIOCGICOUNT ioctl calls, and the (1) mos7720_ioctl function in drivers/usb/serial/mos7720.c and (2) mos7840_ioctl function in drivers/usb/serial/mos7840.c.
2011-01-24 17:28:59 Brad Figg cve linked 2010-4074
2011-01-24 17:30:18 Brad Figg nominated for series Ubuntu Dapper
2011-01-24 17:30:18 Brad Figg nominated for series Ubuntu Hardy
2011-01-24 17:30:18 Brad Figg nominated for series Ubuntu Maverick
2011-01-24 17:30:18 Brad Figg nominated for series Ubuntu Lucid
2011-01-24 17:30:18 Brad Figg nominated for series Ubuntu Karmic
2011-01-24 17:49:20 Brad Figg attachment added hardy: USB: serial/mos*: prevent reading uninitialized stack memory https://bugs.launchpad.net/ubuntu/+source/linux/+bug/706149/+attachment/1805008/+files/0001-USB-serial-mos-prevent-reading-uninitialized-stack-m.patch
2011-01-24 17:49:58 Brad Figg attachment added karmic: USB: serial/mos*: prevent reading uninitialized stack memory https://bugs.launchpad.net/ubuntu/+source/linux/+bug/706149/+attachment/1805009/+files/0001-USB-serial-mos-prevent-reading-uninitialized-stack-m.patch
2011-01-24 17:57:47 Tim Gardner bug task added linux (Ubuntu Dapper)
2011-01-24 17:57:57 Tim Gardner bug task added linux (Ubuntu Hardy)
2011-01-24 17:58:04 Tim Gardner bug task added linux (Ubuntu Karmic)
2011-01-24 17:58:13 Tim Gardner bug task added linux (Ubuntu Lucid)
2011-01-24 17:58:25 Tim Gardner bug task added linux (Ubuntu Maverick)
2011-01-24 18:02:58 Brad Figg linux (Ubuntu Dapper): status New Invalid
2011-01-24 18:03:08 Brad Figg linux (Ubuntu Hardy): status New In Progress
2011-01-24 18:03:17 Brad Figg linux (Ubuntu Karmic): status New In Progress
2011-01-24 18:03:25 Brad Figg linux (Ubuntu Lucid): status New Fix Released
2011-01-24 18:03:33 Brad Figg linux (Ubuntu Maverick): status New Fix Released
2011-01-24 18:03:38 Brad Figg linux (Ubuntu Hardy): assignee Brad Figg (brad-figg)
2011-01-24 18:03:44 Brad Figg linux (Ubuntu Karmic): assignee Brad Figg (brad-figg)
2011-01-25 09:19:56 Andy Whitcroft linux (Ubuntu): status New Fix Released
2011-01-25 09:20:02 Andy Whitcroft linux (Ubuntu): assignee Andy Whitcroft (apw)
2011-01-25 15:17:23 Tim Gardner linux (Ubuntu Hardy): status In Progress Fix Committed
2011-01-25 15:17:43 Tim Gardner linux (Ubuntu Karmic): status In Progress Fix Committed
2011-01-25 15:18:40 Tim Gardner nominated for series Ubuntu Natty
2011-01-25 15:18:40 Tim Gardner bug task added linux (Ubuntu Natty)
2011-01-25 22:51:22 Brian Murray security vulnerability no yes
2011-02-23 21:32:07 Launchpad Janitor linux (Ubuntu Hardy): status Fix Committed Fix Released
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-0435
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-2943
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-3296
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-3297
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-3448
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-3698
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-3699
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-3848
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-3849
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-3850
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-3858
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-3859
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-3873
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-3875
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-3876
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-3877
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-3880
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-4072
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-4078
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-4079
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-4080
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-4081
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-4083
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-4157
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-4160
2011-02-23 21:32:07 Launchpad Janitor cve linked 2010-4248
2011-02-23 21:54:50 Launchpad Janitor linux (Ubuntu Karmic): status Fix Committed Fix Released
2011-02-23 21:54:50 Launchpad Janitor cve linked 2010-3865
2011-02-23 21:54:50 Launchpad Janitor cve linked 2010-3874
2011-02-23 21:54:50 Launchpad Janitor cve linked 2010-4082
2011-02-23 21:54:50 Launchpad Janitor cve linked 2010-4165
2011-02-23 21:54:50 Launchpad Janitor cve linked 2010-4169
2011-02-23 21:54:50 Launchpad Janitor cve linked 2010-4249
2015-02-12 07:07:36 Mathew Hodson cve unlinked 2010-4249