Linux Kernel "L2CAP" and "HCI" Information Disclosure

Wednesday, April 25 2007 @ 01:42 PM EDT

Contributed by: sde

Two weaknesses have been reported in the Linux Kernel, which can be exploited by malicious, local users to disclose potential sensitive information.

The weaknesses are caused due to uninitialised variables within the "hci_sock_setsockopt()" function in net/bluetooth/hci_sock.c and the "l2cap_sock_setsockopt()" function in net/bluetooth/l2cap.c and can potentially be exploited to disclose uninitialised bytes of the kernel stack.

Advisory

0 comments



http://www.linuxlinks.com/portal/news/article.php?story=20070425134246114