Description of problem:
struct sco_conninfo has one padding byte in the end. Local variable
cinfo of type sco_conninfo is copied to userspace with this uninizialized
one byte, leading to old stack contents leak.
Reference:
http://seclists.org/oss-sec/2011/q1/309https://lkml.org/lkml/2011/2/14/49
Acknowledgements:
Red Hat would like to thank Vasiliy Kulikov of Openwall for reporting this issue.
Comment 5Eugene Teo (Security Response)
2011-04-11 04:05:38 UTC