Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Debian_linux | Debian | 2.1 (including) | 2.1 (including) |
| Debian_linux | Debian | 2.2 (including) | 2.2 (including) |
| Mandrake_linux | Mandrakesoft | 6.0 (including) | 6.0 (including) |
| Mandrake_linux | Mandrakesoft | 6.1 (including) | 6.1 (including) |
| Mandrake_linux | Mandrakesoft | 7.0 (including) | 7.0 (including) |
| Mandrake_linux | Mandrakesoft | 7.1 (including) | 7.1 (including) |
| Linux | Redhat | 5.2 (including) | 5.2 (including) |
| Linux | Redhat | 6.2 (including) | 6.2 (including) |
| Slackware_linux | Slackware | * | * |
| Secure_linux | Trustix | 1.1 (including) | 1.1 (including) |