UBUNTU-CVE-2017-7482
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-7482
UBUNTU-CVE-2017-7482
Summary:
Details: In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the data pointer going over the end of the buffer. This could possibly lead to memory corruption and possible privilege escalation.
References: https://ubuntu.com/security/CVE-2017-7482, https://git.kernel.org/torvalds/c/5f2f97656ada8d811d3c1bef503ced266fcd53a0, http://seclists.org/oss-sec/2017/q2/602, https://ubuntu.com/security/notices/USN-3377-1, https://ubuntu.com/security/notices/USN-3377-2, https://ubuntu.com/security/notices/USN-3378-1, https://ubuntu.com/security/notices/USN-3378-2, https://ubuntu.com/security/notices/USN-3381-1, https://ubuntu.com/security/notices/USN-3381-2, https://www.cve.org/CVERecord?id=CVE-2017-7482
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
