CVE: CAN-2003-0984 Updated: Mon, 28 Jun 2004 15:08:24 +0900 Summary: Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space. (text:CAN-2003-0985) Priority: Low Status: Closed Source: RHSA-2003:417-08, RHSA-2004:188-01, FEDORA-2003-046, DSA-413-1 Link: http://www.ultramonkey.org/news_archive.shtml#2004010800 Resolved In: Kernel: 2.4.24-rc1 Patch: http://linux.bkbits.net:8080/linux-2.4/cset@1.1136.94.1??nav=index.html Red Hat Linux 7.3: Vendor: kernel-2.4.20-28.7 UltraMonkey: kernel-2.4.20-28.7.um.1 Red Hat Linux 8.0: Vendor: kernel-2.4.20-28.8 UltraMonkey: kernel-2.4.20-28.8.um.1 Red Hat Linux 9: Vendor: kernel-2.4.20-28.9 UltraMonkey: kernel-2.4.20-28.9.um.1 Fedora Core 1: Vendor: kernel-2.4.22-1.2138.nptl UltraMonkey: kernel-2.4.22-1.2149.nptl.um.2 (initial release) Red Hat Enterprise Linux 3: Vendor: None (patch missing from kernel-2.4.21-15.EL) UltraMonkey: kernel-2.4.21-15.0.2.EL.um.1 Debian Woody: Vendor: None UltraMonkey: kernel-source-2.4.22-1-ipvs_2.4.22-7woody.um.4 Debian Sid: Vendor: kernel-source-2.4.25_2.4.25-1 UltraMonkey: kernel-source-2.4.22-1-ipvs_2.4.22-7.um.4