Title: Linux Kernel ext2 Directory Creation Arbitrary Memory Disclosure
Info
Disclosure
Mar 25, 2005
Discovery
Mar 15, 2005
Dates
Exploit
Jan 01, 2001
Solution
Unknown
Description
The Linux kernel EXT2 filesystem contains a flaw that may lead to an unauthorized information disclosure. The problem is that the 'ext2_make_empty()' function does not properly clear filesystem contents when creating a directory and the block written to store the '.' and '..' directory entries remains uninitialized. Up to 4,072 bytes of kernel memory may be leaked on each directory creation, which may allow a malicious user to disclose sensitive kernel memory contents resulting in a loss of confidentiality.
Classification
Location:
Local Access Required
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
Solution
Upgrade to version 2.4.30-rc2, 2.6.11.6 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.