Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Debian_linux | Debian | 2.1 (including) | 2.1 (including) |
Debian_linux | Debian | 2.2 (including) | 2.2 (including) |
Mandrake_linux | Mandrakesoft | 6.0 (including) | 6.0 (including) |
Mandrake_linux | Mandrakesoft | 6.1 (including) | 6.1 (including) |
Mandrake_linux | Mandrakesoft | 7.0 (including) | 7.0 (including) |
Mandrake_linux | Mandrakesoft | 7.1 (including) | 7.1 (including) |
Linux | Redhat | 5.2 (including) | 5.2 (including) |
Linux | Redhat | 6.2 (including) | 6.2 (including) |
Slackware_linux | Slackware | * | * |
Secure_linux | Trustix | 1.1 (including) | 1.1 (including) |