Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 121033 - CAN-2004-0177 ext3 infoleak
CAN-2004-0177 ext3 infoleak
Product: Red Hat Enterprise Linux 2.1
Classification: Red Hat
Component: kernel (Show other bugs)
i386 Linux
medium Severity low
: ---
: ---
Assigned To: Stephen Tweedie
Brian Brock
: Security
Depends On:
  Show dependency treegraph
Reported: 2004-04-16 08:50 EDT by Mark J. Cox
Modified: 2007-11-30 17:06 EST (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2004-12-13 15:06:39 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2004:505 normal SHIPPED_LIVE Important: Updated kernel packages fix security vulnerability 2004-12-13 00:00:00 EST

  None (edit)
Description Mark J. Cox 2004-04-16 08:50:14 EDT
Whenever you create a file on an ext3fs filesystem, some amount of
other in-memory data, _not_ the file's contents and _not_ something
which is present in the same filesystem or which previously was in a
file at all, gets written to the device holding the filesystem.

Could be a security issue if you have stuff in memory like crypto keys
and don't expect them to get stuck on disk (well unless swapped)

Issue is a fairly minor severity

Reported by Solar Designer of OpenWall on Feb28
Embargo lifted April 14th 2004
Comment 1 John Flanagan 2004-12-13 15:06:39 EST
An errata has been issued which should help the problem 
described in this bug report. This report is therefore being 
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files, 
please follow the link below. You may reopen this bug report 
if the solution does not work for you.


Note You need to log in before you can comment on or make changes to this bug.