oss-sec mailing list archives

Re: CVE-Request: Linux ASLR mmap weakness: Reducing entropy by half


From: Hector Marco <hecmargi () upv es>
Date: Wed, 18 Feb 2015 12:34:39 +0100



El 18/02/15 a las 12:19, Loganaden Velvindron escribió:
On Wed, Feb 18, 2015 at 3:01 PM, Hector Marco <hecmargi () upv es> wrote:
Hi,

A bug in Linux ASLR implementation for versions prior to 3.19 has been
found. The issue is that the mmap area for processes is not properly
randomized on some architectures.

Affected systems have reduced the mmap base area entropy of the processes by
half.


Details at:
http://hmarco.org/bugs/linux-ASLR-reducing-mmap-by-half.html

Hi Hector,

The timeline is not rendered properly on Google chrome browser or
mozilla firefox.

Thank you! Solved it.






Could you please assign a CVE-ID for this?



Hector Marco.
http://hmarco.org

Cyber-security researcher at
http://cybersecurity.upv.es/





Current thread: