Home / vulnerabilitiesPDF  

Linux ASLR Improper Randomization

Posted on 17 February 2015
Source : packetstormsecurity.org Link

 

Hi,

A bug in Linux ASLR implementation for versions prior to 3.19-rc3 has
been found. The issue is that the stack for processes is not properly
randomized on some 64 bit architectures due to an integer overflow.

Affected systems have reduced the stack entropy of the processes by four.

Details at:
http://hmarco.org/bugs/linux-ASLR-integer-overflow.html

Regards,
Hector Marco.
http://hmarco.org

 

TOP