Search

published date: March 9, 2005

CVE-2005-0736 : Integer Overflow Vulnerability

Description

Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel memory via a large number of events.

Product(s):

  • Conectiva Linux 10.0
  • Linux Kernel 2.6.0
  • Linux Kernel 2.6 test10
  • Linux Kernel 2.6 test11
  • Linux Kernel 2.6 test1

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2005-0736, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2005-0736 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?