Bug 425381 (CVE-2007-6416) - CVE-2007-6416 [RHEL 5.2] [XEN/IA64] Security: vulnerability of copy_to_user in PAL emulation
Summary: CVE-2007-6416 [RHEL 5.2] [XEN/IA64] Security: vulnerability of copy_to_user i...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2007-6416
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: ia64
OS: Linux
urgent
high
Target Milestone: ---
Assignee: Jarod Wilson
QA Contact: Martin Jenner
URL:
Whiteboard:
Depends On: 425938 425939
Blocks:
TreeView+ depends on / blocked
 
Reported: 2007-12-14 20:19 UTC by Jarod Wilson
Modified: 2022-04-20 13:04 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2008-07-25 08:56:10 UTC
Embargoed:


Attachments (Terms of Use)
Back-port of copy_to_user fix for RHEL5 (3.16 KB, patch)
2007-12-18 14:43 UTC, Jarod Wilson
no flags Details | Diff


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2008:0089 0 normal SHIPPED_LIVE Important: kernel security and bug fix update 2008-01-23 15:07:09 UTC

Comment 2 Jarod Wilson 2007-12-18 14:43:23 UTC
Created attachment 289892 [details]
Back-port of copy_to_user fix for RHEL5

Comment 3 Mark J. Cox 2008-01-21 10:06:36 UTC
" A security vulnerability was found in Xen's PAL emulation for ia64
machines. Such an HVM guest could access arbitrary physical memory on the
host. This could make sensitive information available to unauthorized
users. (CVE-2007-6416, Important). "

Comment 5 Red Hat Product Security 2008-07-25 08:56:10 UTC
This issue was addressed in:

Red Hat Enterprise Linux:
  http://rhn.redhat.com/errata/RHSA-2008-0089.html




Note You need to log in before you can comment on or make changes to this bug.