Red Hat Bugzilla – Bug 133117
CVE-2004-1058 /proc/<PID>/cmdline information disclosure
Last modified: 2007-11-30 17:06:54 EST
There's a race in the kernel, and considering the permissions on /proc/PID/{cmdline,environ} a security bug as well: If you win the race with a starting process, you can read its environment. http://lkml.org/lkml/2004/7/29/332
Might be 2.6 only fixed in 2.6.9 http://linux.bkbits.net:8080/linux-2.6/cset@412a4baaEebwtKg-X7sS2r5Mua6uGw
I believe RHEL2.1 isn't affected by this flaw and RHEL3 is only affected because of a backported patch. Moving to NEEDINFO for a kernel engineer to verify.
Derry needs this fix. See pensacola BZ 133115 for patch.
An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2006-0190.html