Bug 396751 (CVE-2007-6694)

Summary: CVE-2007-6694 /proc/cpuinfo DoS on some ppc machines
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: kreilly, kseifried, williams
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-09-29 22:03:56 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On: 396771, 396781, 396791, 396801, 396811, 396821, 396831    
Bug Blocks:    
Description Flags
Patch from the reporter. none

Description Jan Lieskovsky 2007-11-23 13:46:00 UTC
Description of problem:

This patch does fix possible NULL pointer dereference
inside of strncmp() if of_get_property() failed. 

This issue went public via: 


Comment 1 Jan Lieskovsky 2007-11-23 13:46:48 UTC
This one has not CVE number assigned yet, will update this one as soon as
this gets one. 

Comment 2 Jan Lieskovsky 2007-11-23 13:49:34 UTC
Created attachment 267541 [details]
Patch from the reporter.

Attaching patch from the reporter.