Bug 377591 (CVE-2007-5908)
| Summary: | CVE-2007-5908 Buffer overflow in the (1) sysfs_show_available_clocksources and (2) sysfs_show_current_clocksources functions in Linux kernel | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> |
| Component: | vulnerability | Assignee: | Dave Jones <davej> |
| Status: | CLOSED WONTFIX | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | anton, esandeen, kernel-maint, kreilly, pfrields, security-response-team |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2008-03-12 10:28:10 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 378351, 378361 | ||
| Bug Blocks: | |||
|
Description
Jan Lieskovsky
2007-11-12 11:31:29 UTC
This does not look like it can actually happen. The list of available clocksources is very short and they all have short names. So far looks like nothing committed upstream on this one, either. Re: c#3: Chuck so this means, you don't want to fix this one? Re: c#4: Eric, maybe you could initiate the commit to RH kernel mailing list? Based on c#3 and further investigation closing this one as WONTFIX. |