Action not permitted
Modal body text goes here.
Modal Title
Modal Body
BDU:2015-01499 (CVE-2008-3527)
Vulnerability from fstec – Published: 2016-07-06 – Updated: 2016-11-28 – View on bdu.fstec.ru Fixed
VLAI
Title
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации
Summary
Множественные уязвимости пакета linux-headers-2.6.18-6-parisc64-smp операционной системы Debian GNU/Linux, эксплуатация которых может привести к нарушению доступности защищаемой информации. Эксплуатация уязвимостей может быть осуществлена удаленно.
Severity
Status
Confirmed by the vendor
Exploitation
Being clarified
Incidents
Being clarified
Remediation
Being clarified
Aliases
References
9 references
Impacted products
1 product
from 1 vendor
Vendors
Сообщество свободного программного обеспечения
Products
Debian GNU/Linux
Versions
до 4 (Debian GNU/Linux)
Product types
Operating system
Mitigations
Проблема может быть решена обновлением операционной системы до следующих версий пакетов в зависимости от архитектуры:
Debian GNU/Linux 4:
ppc:
linux-headers-2.6.18-6-powerpc - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1
fai-kernels - 1.17+etch.23etch1
linux-image-2.6.18-6-powerpc64 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-powerpc-miboot - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-vserver-powerpc64 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-powerpc64 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-all-powerpc - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-powerpc - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-powerpc-miboot - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-vserver-powerpc - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-powerpc-smp - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-vserver-powerpc64 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-prep - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-prep - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-vserver-powerpc - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-vserver - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-powerpc-smp - 2.6.18.dfsg.1-23etch1
s390x:
linux-headers-2.6.18-6-vserver - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-s390-tape - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-s390 - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-s390 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-s390x - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-s390x - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-all-s390 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-vserver-s390x - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-vserver-s390x - 2.6.18.dfsg.1-23etch1
i686:
linux-headers-2.6.18-6-xen - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-vserver-686 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-xen-vserver - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-486 - 2.6.18.dfsg.1-23etch1
linux-modules-2.6.18-6-xen-686 - 2.6.18.dfsg.1-23etch1
user-mode-linux - 2.6.18-1um-2etch.23etch1
linux-image-2.6.18-6-686-bigmem - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-xen-vserver-686 - 2.6.18.dfsg.1-23etch1
fai-kernels - 1.17+etch.23etch1
xen-linux-system-2.6.18-6-xen-vserver-686 - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-k7 - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-xen-vserver-686 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-k7 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-xen-686 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-vserver - 2.6.18.dfsg.1-23etch1
linux-modules-2.6.18-6-xen-vserver-686 - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-amd64 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-686-bigmem - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-686 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-all-i386 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1
xen-linux-system-2.6.18-6-xen-686 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-vserver-k7 - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-vserver-686 - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-vserver-k7 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-686 - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-486 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-amd64 - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-xen-686 - 2.6.18.dfsg.1-23etch1
hppa:
linux-image-2.6.18-6-parisc64-smp - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-parisc-smp - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-all-hppa - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-parisc-smp - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-parisc - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-parisc64 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-parisc64-smp - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-parisc64 - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-parisc - 2.6.18.dfsg.1-23etch1
sparc:
linux-image-2.6.18-6-vserver-sparc64 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-sparc64 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-vserver-sparc64 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-all-sparc - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-sparc32 - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-sparc64 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-sparc64-smp - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-vserver - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-sparc32 - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-sparc64-smp - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1
x86-64:
linux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1
linux-modules-2.6.18-6-xen-amd64 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-xen-vserver-amd64 - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-vserver-amd64 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-amd64 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-xen-vserver - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-all-amd64 - 2.6.18.dfsg.1-23etch1
linux-modules-2.6.18-6-xen-vserver-amd64 - 2.6.18.dfsg.1-23etch1
fai-kernels - 1.17+etch.23etch1
linux-headers-2.6.18-6-vserver - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-xen - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-xen-amd64 - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-amd64 - 2.6.18.dfsg.1-23etch1
xen-linux-system-2.6.18-6-xen-amd64 - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-xen-vserver-amd64 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-vserver-amd64 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-xen-amd64 - 2.6.18.dfsg.1-23etch1
xen-linux-system-2.6.18-6-xen-vserver-amd64 - 2.6.18.dfsg.1-23etch1
alpha:
linux-headers-2.6.18-6-alpha-generic - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-alpha-legacy - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-alpha-legacy - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-vserver-alpha - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-vserver-alpha - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-all-alpha - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-alpha-smp - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-vserver - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-alpha-smp - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-alpha-generic - 2.6.18.dfsg.1-23etch1
ia64:
linux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-all-ia64 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-itanium - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-itanium - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-mckinley - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-mckinley - 2.6.18.dfsg.1-23etch1
mips:
linux-image-2.6.18-6-qemu - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-sb1a-bcm91480b - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-r5k-ip32 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-qemu - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-r4k-ip22 - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-sb1-bcm91250a - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-all-mips - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-r5k-ip32 - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-r4k-ip22 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-sb1-bcm91250a - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-sb1a-bcm91480b - 2.6.18.dfsg.1-23etch1
noarch:
linux-patch-debian-2.6.18 - 2.6.18.dfsg.1-23etch1
linux-source-2.6.18 - 2.6.18.dfsg.1-23etch1
linux-doc-2.6.18 - 2.6.18.dfsg.1-23etch1
linux-tree-2.6.18 - 2.6.18.dfsg.1-23etch1
linux-manual-2.6.18 - 2.6.18.dfsg.1-23etch1
linux-support-2.6.18-6 - 2.6.18.dfsg.1-23etch1
mipsel:
linux-image-2.6.18-6-r5k-cobalt - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-sb1-bcm91250a - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-sb1a-bcm91480b - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-r4k-kn04 - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-qemu - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-r5k-cobalt - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-r3k-kn02 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-r3k-kn02 - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-sb1a-bcm91480b - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-r4k-kn04 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-qemu - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-sb1-bcm91250a - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-all-mipsel - 2.6.18.dfsg.1-23etch1
arm:
linux-image-2.6.18-6-ixp4xx - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-iop32x - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-footbridge - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-rpc - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-rpc - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-s3c2410 - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-iop32x - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-all-arm - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-s3c2410 - 2.6.18.dfsg.1-23etch1
linux-headers-2.6.18-6-ixp4xx - 2.6.18.dfsg.1-23etch1
linux-image-2.6.18-6-footbridge - 2.6.18.dfsg.1-23etch1
{
"CVSS 2.0": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"CVSS 3.0": null,
"CVSS 4.0": null,
"remediation_\u0418\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0440": null,
"remediation_\u041d\u0430\u0438\u043c\u0435\u043d\u043e\u0432\u0430\u043d\u0438\u0435": null,
"\u0412\u0435\u043d\u0434\u043e\u0440 \u041f\u041e": "\u0421\u043e\u043e\u0431\u0449\u0435\u0441\u0442\u0432\u043e \u0441\u0432\u043e\u0431\u043e\u0434\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u043e\u0433\u043e \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f",
"\u0412\u0435\u0440\u0441\u0438\u044f \u041f\u041e": "\u0434\u043e 4 (Debian GNU/Linux)",
"\u0412\u043e\u0437\u043c\u043e\u0436\u043d\u044b\u0435 \u043c\u0435\u0440\u044b \u043f\u043e \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044e": "\u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u0440\u0435\u0448\u0435\u043d\u0430 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435\u043c \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0434\u043e \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0445 \u0432\u0435\u0440\u0441\u0438\u0439 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0432 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438 \u043e\u0442 \u0430\u0440\u0445\u0438\u0442\u0435\u043a\u0442\u0443\u0440\u044b:\nDebian GNU/Linux 4:\n\tppc:\n\t\tlinux-headers-2.6.18-6-powerpc - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1\n\t\tfai-kernels - 1.17+etch.23etch1\n\t\tlinux-image-2.6.18-6-powerpc64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-powerpc-miboot - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-vserver-powerpc64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-powerpc64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-all-powerpc - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-powerpc - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-powerpc-miboot - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-vserver-powerpc - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-powerpc-smp - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-vserver-powerpc64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-prep - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-prep - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-vserver-powerpc - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-vserver - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-powerpc-smp - 2.6.18.dfsg.1-23etch1\n\ts390x:\n\t\tlinux-headers-2.6.18-6-vserver - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-s390-tape - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-s390 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-s390 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-s390x - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-s390x - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-all-s390 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-vserver-s390x - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-vserver-s390x - 2.6.18.dfsg.1-23etch1\n\ti686:\n\t\tlinux-headers-2.6.18-6-xen - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-vserver-686 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-xen-vserver - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-486 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-modules-2.6.18-6-xen-686 - 2.6.18.dfsg.1-23etch1\n\t\tuser-mode-linux - 2.6.18-1um-2etch.23etch1\n\t\tlinux-image-2.6.18-6-686-bigmem - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-xen-vserver-686 - 2.6.18.dfsg.1-23etch1\n\t\tfai-kernels - 1.17+etch.23etch1\n\t\txen-linux-system-2.6.18-6-xen-vserver-686 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-k7 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-xen-vserver-686 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-k7 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-xen-686 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-vserver - 2.6.18.dfsg.1-23etch1\n\t\tlinux-modules-2.6.18-6-xen-vserver-686 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-amd64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-686-bigmem - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-686 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-all-i386 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1\n\t\txen-linux-system-2.6.18-6-xen-686 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-vserver-k7 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-vserver-686 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-vserver-k7 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-686 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-486 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-amd64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-xen-686 - 2.6.18.dfsg.1-23etch1\n\thppa:\n\t\tlinux-image-2.6.18-6-parisc64-smp - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-parisc-smp - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-all-hppa - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-parisc-smp - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-parisc - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-parisc64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-parisc64-smp - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-parisc64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-parisc - 2.6.18.dfsg.1-23etch1\n\tsparc:\n\t\tlinux-image-2.6.18-6-vserver-sparc64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-sparc64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-vserver-sparc64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-all-sparc - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-sparc32 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-sparc64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-sparc64-smp - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-vserver - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-sparc32 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-sparc64-smp - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1\n\tx86-64:\n\t\tlinux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-modules-2.6.18-6-xen-amd64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-xen-vserver-amd64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-vserver-amd64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-amd64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-xen-vserver - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-all-amd64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-modules-2.6.18-6-xen-vserver-amd64 - 2.6.18.dfsg.1-23etch1\n\t\tfai-kernels - 1.17+etch.23etch1\n\t\tlinux-headers-2.6.18-6-vserver - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-xen - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-xen-amd64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-amd64 - 2.6.18.dfsg.1-23etch1\n\t\txen-linux-system-2.6.18-6-xen-amd64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-xen-vserver-amd64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-vserver-amd64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-xen-amd64 - 2.6.18.dfsg.1-23etch1\n\t\txen-linux-system-2.6.18-6-xen-vserver-amd64 - 2.6.18.dfsg.1-23etch1\n\talpha:\n\t\tlinux-headers-2.6.18-6-alpha-generic - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-alpha-legacy - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-alpha-legacy - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-vserver-alpha - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-vserver-alpha - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-all-alpha - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-alpha-smp - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-vserver - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-alpha-smp - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-alpha-generic - 2.6.18.dfsg.1-23etch1\n\tia64:\n\t\tlinux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-all-ia64 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-itanium - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-itanium - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-mckinley - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-mckinley - 2.6.18.dfsg.1-23etch1\n\tmips:\n\t\tlinux-image-2.6.18-6-qemu - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-sb1a-bcm91480b - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-r5k-ip32 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-qemu - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-r4k-ip22 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-sb1-bcm91250a - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-all-mips - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-r5k-ip32 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-r4k-ip22 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-sb1-bcm91250a - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-sb1a-bcm91480b - 2.6.18.dfsg.1-23etch1\n\tnoarch:\n\t\tlinux-patch-debian-2.6.18 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-source-2.6.18 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-doc-2.6.18 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-tree-2.6.18 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-manual-2.6.18 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-support-2.6.18-6 - 2.6.18.dfsg.1-23etch1\n\tmipsel:\n\t\tlinux-image-2.6.18-6-r5k-cobalt - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-sb1-bcm91250a - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-sb1a-bcm91480b - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-r4k-kn04 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-qemu - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-r5k-cobalt - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-r3k-kn02 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-r3k-kn02 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-sb1a-bcm91480b - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-r4k-kn04 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-qemu - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-sb1-bcm91250a - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-all-mipsel - 2.6.18.dfsg.1-23etch1\n\tarm:\n\t\tlinux-image-2.6.18-6-ixp4xx - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-iop32x - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-footbridge - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-rpc - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-rpc - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-s3c2410 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-iop32x - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-all-arm - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-all - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-s3c2410 - 2.6.18.dfsg.1-23etch1\n\t\tlinux-headers-2.6.18-6-ixp4xx - 2.6.18.dfsg.1-23etch1\n\t\tlinux-image-2.6.18-6-footbridge - 2.6.18.dfsg.1-23etch1",
"\u0414\u0430\u0442\u0430 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f": null,
"\u0414\u0430\u0442\u0430 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0435\u0433\u043e \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f": "28.11.2016",
"\u0414\u0430\u0442\u0430 \u043f\u0443\u0431\u043b\u0438\u043a\u0430\u0446\u0438\u0438": "06.07.2016",
"\u0418\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0440": "BDU:2015-01499",
"\u0418\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0440\u044b \u0434\u0440\u0443\u0433\u0438\u0445 \u0441\u0438\u0441\u0442\u0435\u043c \u043e\u043f\u0438\u0441\u0430\u043d\u0438\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": "CVE-2008-3527, CVE-2008-3528, CVE-2008-4554, CVE-2008-4576, CVE-2008-4933, CVE-2008-4934, CVE-2008-5025, CVE-2008-5029, DSA-1687, ID:1400191",
"\u0418\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e\u0431 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0438": "\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430",
"\u041a\u043b\u0430\u0441\u0441 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": null,
"\u041d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 \u041f\u041e": "Debian GNU/Linux",
"\u041d\u0430\u0438\u043c\u0435\u043d\u043e\u0432\u0430\u043d\u0438\u0435 \u041e\u0421 \u0438 \u0442\u0438\u043f \u0430\u043f\u043f\u0430\u0440\u0430\u0442\u043d\u043e\u0439 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b": null,
"\u041d\u0430\u0438\u043c\u0435\u043d\u043e\u0432\u0430\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": "\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b Debian\u00a0GNU/Linux, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0443\u0434\u0430\u043b\u0435\u043d\u043d\u043e\u043c\u0443 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0443 \u043d\u0430\u0440\u0443\u0448\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u043e\u0441\u0442\u044c \u0437\u0430\u0449\u0438\u0449\u0430\u0435\u043c\u043e\u0439 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438",
"\u041d\u0430\u043b\u0438\u0447\u0438\u0435 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430": "\u0414\u0430\u043d\u043d\u044b\u0435 \u0443\u0442\u043e\u0447\u043d\u044f\u044e\u0442\u0441\u044f",
"\u041e\u043f\u0438\u0441\u0430\u043d\u0438\u0435 \u043e\u0448\u0438\u0431\u043a\u0438 CWE": null,
"\u041e\u043f\u0438\u0441\u0430\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": "\u041c\u043d\u043e\u0436\u0435\u0441\u0442\u0432\u0435\u043d\u043d\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0430\u043a\u0435\u0442\u0430 linux-headers-2.6.18-6-parisc64-smp \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b Debian\u00a0GNU/Linux, \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u044f \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u043d\u0430\u0440\u0443\u0448\u0435\u043d\u0438\u044e \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u043e\u0441\u0442\u0438 \u0437\u0430\u0449\u0438\u0449\u0430\u0435\u043c\u043e\u0439 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438. \u042d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u043b\u0435\u043d\u0430 \u0443\u0434\u0430\u043b\u0435\u043d\u043d\u043e.",
"\u041f\u043e\u0441\u043b\u0435\u0434\u0441\u0442\u0432\u0438\u044f \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": null,
"\u041f\u0440\u043e\u0447\u0430\u044f \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f": null,
"\u0421\u0432\u044f\u0437\u044c \u0441 \u0438\u043d\u0446\u0438\u0434\u0435\u043d\u0442\u0430\u043c\u0438 \u0418\u0411": "\u0414\u0430\u043d\u043d\u044b\u0435 \u0443\u0442\u043e\u0447\u043d\u044f\u044e\u0442\u0441\u044f",
"\u0421\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": "\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u0430",
"\u0421\u043f\u043e\u0441\u043e\u0431 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044f": "\u0414\u0430\u043d\u043d\u044b\u0435 \u0443\u0442\u043e\u0447\u043d\u044f\u044e\u0442\u0441\u044f",
"\u0421\u043f\u043e\u0441\u043e\u0431 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438": "\u0414\u0430\u043d\u043d\u044b\u0435 \u0443\u0442\u043e\u0447\u043d\u044f\u044e\u0442\u0441\u044f",
"\u0421\u0441\u044b\u043b\u043a\u0438 \u043d\u0430 \u0438\u0441\u0442\u043e\u0447\u043d\u0438\u043a\u0438": "http://www.debian.org/security/dsa-1687/\nhttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4554\nhttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3527\nhttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5029\nhttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4933\nhttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4934\nhttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4576\nhttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5025\nhttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3528",
"\u0421\u0442\u0430\u0442\u0443\u0441 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": "\u041f\u043e\u0434\u0442\u0432\u0435\u0440\u0436\u0434\u0435\u043d\u0430 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u0435\u043c",
"\u0422\u0438\u043f \u041f\u041e": "\u041e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u0430\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u0430",
"\u0422\u0438\u043f \u043e\u0448\u0438\u0431\u043a\u0438 CWE": null,
"\u0423\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438": "\u0412\u044b\u0441\u043e\u043a\u0438\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 (\u0431\u0430\u0437\u043e\u0432\u0430\u044f \u043e\u0446\u0435\u043d\u043a\u0430 CVSS 2.0 \u0441\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 7,8)"
}
CVE-2008-3527 (GCVE-0-2008-3527)
Vulnerability from cvelistv5 – Published: 2008-11-05 14:51 – Updated: 2024-08-07 09:45
VLAI
EPSS
VEX
Summary
arch/i386/kernel/sysenter.c in the Virtual Dynamic Shared Objects (vDSO) implementation in the Linux kernel before 2.6.21 does not properly check boundaries, which allows local users to gain privileges or cause a denial of service via unspecified vectors, related to the install_special_mapping, syscall, and syscall32_nopage functions.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
11 references
| URL | Tags |
|---|---|
| http://secunia.com/advisories/32485 | third-party-advisoryx_refsource_SECUNIA |
| https://oval.cisecurity.org/repository/search/def… | vdb-entrysignaturex_refsource_OVAL |
| http://git.kernel.org/?p=linux/kernel/git/torvald… | x_refsource_CONFIRM |
| http://www.kernel.org/pub/linux/kernel/v2.6/Chang… | x_refsource_CONFIRM |
| http://www.redhat.com/support/errata/RHSA-2008-09… | vendor-advisoryx_refsource_REDHAT |
| http://www.securitytracker.com/id?1021137 | vdb-entryx_refsource_SECTRACK |
| https://bugzilla.redhat.com/show_bug.cgi?id=460251 | x_refsource_CONFIRM |
| http://www.debian.org/security/2008/dsa-1687 | vendor-advisoryx_refsource_DEBIAN |
| http://secunia.com/advisories/32759 | third-party-advisoryx_refsource_SECUNIA |
| http://secunia.com/advisories/33180 | third-party-advisoryx_refsource_SECUNIA |
| http://lists.opensuse.org/opensuse-security-annou… | vendor-advisoryx_refsource_SUSE |
Date Public
2008-11-04 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-07T09:45:18.183Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "32485",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32485"
},
{
"name": "oval:org.mitre.oval:def:10602",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL",
"x_transferred"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10602"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7d91d531900bfa1165d445390b3b13a8013f98f7"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.21"
},
{
"name": "RHSA-2008:0957",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT",
"x_transferred"
],
"url": "http://www.redhat.com/support/errata/RHSA-2008-0957.html"
},
{
"name": "1021137",
"tags": [
"vdb-entry",
"x_refsource_SECTRACK",
"x_transferred"
],
"url": "http://www.securitytracker.com/id?1021137"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=460251"
},
{
"name": "DSA-1687",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN",
"x_transferred"
],
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"name": "32759",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32759"
},
{
"name": "33180",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33180"
},
{
"name": "SUSE-SR:2008:025",
"tags": [
"vendor-advisory",
"x_refsource_SUSE",
"x_transferred"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2008-11-04T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "arch/i386/kernel/sysenter.c in the Virtual Dynamic Shared Objects (vDSO) implementation in the Linux kernel before 2.6.21 does not properly check boundaries, which allows local users to gain privileges or cause a denial of service via unspecified vectors, related to the install_special_mapping, syscall, and syscall32_nopage functions."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-09-28T12:57:01.000Z",
"orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
"shortName": "redhat"
},
"references": [
{
"name": "32485",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32485"
},
{
"name": "oval:org.mitre.oval:def:10602",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10602"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7d91d531900bfa1165d445390b3b13a8013f98f7"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.21"
},
{
"name": "RHSA-2008:0957",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "http://www.redhat.com/support/errata/RHSA-2008-0957.html"
},
{
"name": "1021137",
"tags": [
"vdb-entry",
"x_refsource_SECTRACK"
],
"url": "http://www.securitytracker.com/id?1021137"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=460251"
},
{
"name": "DSA-1687",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN"
],
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"name": "32759",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32759"
},
{
"name": "33180",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33180"
},
{
"name": "SUSE-SR:2008:025",
"tags": [
"vendor-advisory",
"x_refsource_SUSE"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
"assignerShortName": "redhat",
"cveId": "CVE-2008-3527",
"datePublished": "2008-11-05T14:51:00.000Z",
"dateReserved": "2008-08-07T00:00:00.000Z",
"dateUpdated": "2024-08-07T09:45:18.183Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2008-3528 (GCVE-0-2008-3528)
Vulnerability from cvelistv5 – Published: 2008-09-27 00:00 – Updated: 2024-08-07 09:45
VLAI
EPSS
VEX
Summary
The error-reporting functionality in (1) fs/ext2/dir.c, (2) fs/ext3/dir.c, and possibly (3) fs/ext4/dir.c in the Linux kernel 2.6.26.5 does not limit the number of printk console messages that report directory corruption, which allows physically proximate attackers to cause a denial of service (temporary system hang) by mounting a filesystem that has corrupted dir->i_size and dir->i_blocks values and performing (a) read or (b) write operations. NOTE: there are limited scenarios in which this crosses privilege boundaries.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
38 references
Date Public
2008-09-18 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-07T09:45:17.864Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "32998",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32998"
},
{
"name": "[oss-security] 20080918 CVE-2008-3528 Linux kernel ext[234] directory corruption DoS",
"tags": [
"mailing-list",
"x_refsource_MLIST",
"x_transferred"
],
"url": "http://www.openwall.com/lists/oss-security/2008/09/18/2"
},
{
"name": "RHSA-2009:0326",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT",
"x_transferred"
],
"url": "http://www.redhat.com/support/errata/RHSA-2009-0326.html"
},
{
"name": "[linux-kernel] 20080918 Re: [PATCH 4/4] ext3: Avoid printk floods in the face of directory corruption",
"tags": [
"mailing-list",
"x_refsource_MLIST",
"x_transferred"
],
"url": "http://lkml.org/lkml/2008/9/17/371"
},
{
"name": "MDVSA-2008:224",
"tags": [
"vendor-advisory",
"x_refsource_MANDRIVA",
"x_transferred"
],
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:224"
},
{
"name": "37471",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/37471"
},
{
"name": "[linux-kernel] 20080913 [PATCH 3/4] ext2: Avoid printk floods in the face of directory corruption",
"tags": [
"mailing-list",
"x_refsource_MLIST",
"x_transferred"
],
"url": "http://lkml.org/lkml/2008/9/13/98"
},
{
"name": "RHSA-2008:0972",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT",
"x_transferred"
],
"url": "http://rhn.redhat.com/errata/RHSA-2008-0972.html"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://www.vmware.com/security/advisories/VMSA-2009-0016.html"
},
{
"name": "SUSE-SA:2008:052",
"tags": [
"vendor-advisory",
"x_refsource_SUSE",
"x_transferred"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00008.html"
},
{
"name": "33758",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33758"
},
{
"name": "RHSA-2009:0009",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT",
"x_transferred"
],
"url": "http://www.redhat.com/support/errata/RHSA-2009-0009.html"
},
{
"name": "SUSE-SA:2008:053",
"tags": [
"vendor-advisory",
"x_refsource_SUSE",
"x_transferred"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00010.html"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=459577"
},
{
"name": "kernel-errorreporting-dos(45720)",
"tags": [
"vdb-entry",
"x_refsource_XF",
"x_transferred"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45720"
},
{
"name": "SUSE-SA:2008:056",
"tags": [
"vendor-advisory",
"x_refsource_SUSE",
"x_transferred"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00000.html"
},
{
"name": "USN-662-1",
"tags": [
"vendor-advisory",
"x_refsource_UBUNTU",
"x_transferred"
],
"url": "http://www.ubuntu.com/usn/usn-662-1"
},
{
"name": "33586",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33586"
},
{
"name": "32509",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32509"
},
{
"name": "20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ",
"x_transferred"
],
"url": "http://www.securityfocus.com/archive/1/507985/100/0/threaded"
},
{
"name": "32709",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32709"
},
{
"name": "DSA-1687",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN",
"x_transferred"
],
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"name": "32356",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32356"
},
{
"name": "oval:org.mitre.oval:def:8642",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL",
"x_transferred"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8642"
},
{
"name": "oval:org.mitre.oval:def:10852",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL",
"x_transferred"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10852"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://wiki.rpath.com/Advisories:rPSA-2008-0316"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0316"
},
{
"name": "32759",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32759"
},
{
"name": "[linux-kernel] 20080913 [PATCH 4/4] ext3: Avoid printk floods in the face of directory corruption",
"tags": [
"mailing-list",
"x_refsource_MLIST",
"x_transferred"
],
"url": "http://lkml.org/lkml/2008/9/13/99"
},
{
"name": "33180",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33180"
},
{
"name": "32370",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32370"
},
{
"name": "SUSE-SA:2008:051",
"tags": [
"vendor-advisory",
"x_refsource_SUSE",
"x_transferred"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00007.html"
},
{
"name": "32799",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32799"
},
{
"name": "SUSE-SA:2008:057",
"tags": [
"vendor-advisory",
"x_refsource_SUSE",
"x_transferred"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00001.html"
},
{
"name": "SUSE-SR:2008:025",
"tags": [
"vendor-advisory",
"x_refsource_SUSE",
"x_transferred"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html"
},
{
"name": "DSA-1681",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN",
"x_transferred"
],
"url": "http://www.debian.org/security/2008/dsa-1681"
},
{
"name": "ADV-2009-3316",
"tags": [
"vdb-entry",
"x_refsource_VUPEN",
"x_transferred"
],
"url": "http://www.vupen.com/english/advisories/2009/3316"
},
{
"name": "20081112 rPSA-2008-0316-1 kernel",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ",
"x_transferred"
],
"url": "http://www.securityfocus.com/archive/1/498285/100/0/threaded"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2008-09-18T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "The error-reporting functionality in (1) fs/ext2/dir.c, (2) fs/ext3/dir.c, and possibly (3) fs/ext4/dir.c in the Linux kernel 2.6.26.5 does not limit the number of printk console messages that report directory corruption, which allows physically proximate attackers to cause a denial of service (temporary system hang) by mounting a filesystem that has corrupted dir-\u003ei_size and dir-\u003ei_blocks values and performing (a) read or (b) write operations. NOTE: there are limited scenarios in which this crosses privilege boundaries."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2018-10-11T19:57:01.000Z",
"orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
"shortName": "redhat"
},
"references": [
{
"name": "32998",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32998"
},
{
"name": "[oss-security] 20080918 CVE-2008-3528 Linux kernel ext[234] directory corruption DoS",
"tags": [
"mailing-list",
"x_refsource_MLIST"
],
"url": "http://www.openwall.com/lists/oss-security/2008/09/18/2"
},
{
"name": "RHSA-2009:0326",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "http://www.redhat.com/support/errata/RHSA-2009-0326.html"
},
{
"name": "[linux-kernel] 20080918 Re: [PATCH 4/4] ext3: Avoid printk floods in the face of directory corruption",
"tags": [
"mailing-list",
"x_refsource_MLIST"
],
"url": "http://lkml.org/lkml/2008/9/17/371"
},
{
"name": "MDVSA-2008:224",
"tags": [
"vendor-advisory",
"x_refsource_MANDRIVA"
],
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:224"
},
{
"name": "37471",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/37471"
},
{
"name": "[linux-kernel] 20080913 [PATCH 3/4] ext2: Avoid printk floods in the face of directory corruption",
"tags": [
"mailing-list",
"x_refsource_MLIST"
],
"url": "http://lkml.org/lkml/2008/9/13/98"
},
{
"name": "RHSA-2008:0972",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "http://rhn.redhat.com/errata/RHSA-2008-0972.html"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://www.vmware.com/security/advisories/VMSA-2009-0016.html"
},
{
"name": "SUSE-SA:2008:052",
"tags": [
"vendor-advisory",
"x_refsource_SUSE"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00008.html"
},
{
"name": "33758",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33758"
},
{
"name": "RHSA-2009:0009",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "http://www.redhat.com/support/errata/RHSA-2009-0009.html"
},
{
"name": "SUSE-SA:2008:053",
"tags": [
"vendor-advisory",
"x_refsource_SUSE"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00010.html"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=459577"
},
{
"name": "kernel-errorreporting-dos(45720)",
"tags": [
"vdb-entry",
"x_refsource_XF"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45720"
},
{
"name": "SUSE-SA:2008:056",
"tags": [
"vendor-advisory",
"x_refsource_SUSE"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00000.html"
},
{
"name": "USN-662-1",
"tags": [
"vendor-advisory",
"x_refsource_UBUNTU"
],
"url": "http://www.ubuntu.com/usn/usn-662-1"
},
{
"name": "33586",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33586"
},
{
"name": "32509",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32509"
},
{
"name": "20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ"
],
"url": "http://www.securityfocus.com/archive/1/507985/100/0/threaded"
},
{
"name": "32709",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32709"
},
{
"name": "DSA-1687",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN"
],
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"name": "32356",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32356"
},
{
"name": "oval:org.mitre.oval:def:8642",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8642"
},
{
"name": "oval:org.mitre.oval:def:10852",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10852"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://wiki.rpath.com/Advisories:rPSA-2008-0316"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0316"
},
{
"name": "32759",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32759"
},
{
"name": "[linux-kernel] 20080913 [PATCH 4/4] ext3: Avoid printk floods in the face of directory corruption",
"tags": [
"mailing-list",
"x_refsource_MLIST"
],
"url": "http://lkml.org/lkml/2008/9/13/99"
},
{
"name": "33180",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33180"
},
{
"name": "32370",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32370"
},
{
"name": "SUSE-SA:2008:051",
"tags": [
"vendor-advisory",
"x_refsource_SUSE"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00007.html"
},
{
"name": "32799",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32799"
},
{
"name": "SUSE-SA:2008:057",
"tags": [
"vendor-advisory",
"x_refsource_SUSE"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00001.html"
},
{
"name": "SUSE-SR:2008:025",
"tags": [
"vendor-advisory",
"x_refsource_SUSE"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html"
},
{
"name": "DSA-1681",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN"
],
"url": "http://www.debian.org/security/2008/dsa-1681"
},
{
"name": "ADV-2009-3316",
"tags": [
"vdb-entry",
"x_refsource_VUPEN"
],
"url": "http://www.vupen.com/english/advisories/2009/3316"
},
{
"name": "20081112 rPSA-2008-0316-1 kernel",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ"
],
"url": "http://www.securityfocus.com/archive/1/498285/100/0/threaded"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
"assignerShortName": "redhat",
"cveId": "CVE-2008-3528",
"datePublished": "2008-09-27T00:00:00.000Z",
"dateReserved": "2008-08-07T00:00:00.000Z",
"dateUpdated": "2024-08-07T09:45:17.864Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2008-4554 (GCVE-0-2008-4554)
Vulnerability from cvelistv5 – Published: 2008-10-15 19:00 – Updated: 2024-08-07 10:17
VLAI
EPSS
VEX
Summary
The do_splice_from function in fs/splice.c in the Linux kernel before 2.6.27 does not reject file descriptors that have the O_APPEND flag set, which allows local users to bypass append mode and make arbitrary changes to other locations in the file.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
24 references
Date Public
2008-10-09 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-07T10:17:09.869Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "35390",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/35390"
},
{
"name": "32998",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32998"
},
{
"name": "[oss-security] 20081013 CVE request: kernel: don\u0027t allow splice() to files opened with O_APPEND",
"tags": [
"mailing-list",
"x_refsource_MLIST",
"x_transferred"
],
"url": "http://www.openwall.com/lists/oss-security/2008/10/13/1"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=466707"
},
{
"name": "MDVSA-2008:224",
"tags": [
"vendor-advisory",
"x_refsource_MANDRIVA",
"x_transferred"
],
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:224"
},
{
"name": "oval:org.mitre.oval:def:11142",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL",
"x_transferred"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11142"
},
{
"name": "linux-kernel-dosplicefrom-security-bypass(45954)",
"tags": [
"vdb-entry",
"x_refsource_XF",
"x_transferred"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45954"
},
{
"name": "31903",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/31903"
},
{
"name": "RHSA-2009:0009",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT",
"x_transferred"
],
"url": "http://www.redhat.com/support/errata/RHSA-2009-0009.html"
},
{
"name": "SUSE-SA:2009:030",
"tags": [
"vendor-advisory",
"x_refsource_SUSE",
"x_transferred"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html"
},
{
"name": "FEDORA-2008-8929",
"tags": [
"vendor-advisory",
"x_refsource_FEDORA",
"x_transferred"
],
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00693.html"
},
{
"name": "[oss-security] 20081014 Re: CVE request: kernel: don\u0027t allow splice() to files opened with O_APPEND",
"tags": [
"mailing-list",
"x_refsource_MLIST",
"x_transferred"
],
"url": "http://www.openwall.com/lists/oss-security/2008/10/14/5"
},
{
"name": "33586",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33586"
},
{
"name": "DSA-1687",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN",
"x_transferred"
],
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.26.y.git%3Ba=commit%3Bh=efc968d450e013049a662d22727cf132618dcb2f"
},
{
"name": "32918",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32918"
},
{
"name": "USN-679-1",
"tags": [
"vendor-advisory",
"x_refsource_UBUNTU",
"x_transferred"
],
"url": "http://www.ubuntu.com/usn/usn-679-1"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27"
},
{
"name": "33180",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33180"
},
{
"name": "RHSA-2008:1017",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT",
"x_transferred"
],
"url": "http://www.redhat.com/support/errata/RHSA-2008-1017.html"
},
{
"name": "32386",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32386"
},
{
"name": "FEDORA-2008-8980",
"tags": [
"vendor-advisory",
"x_refsource_FEDORA",
"x_transferred"
],
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00689.html"
},
{
"name": "DSA-1681",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN",
"x_transferred"
],
"url": "http://www.debian.org/security/2008/dsa-1681"
},
{
"name": "33182",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33182"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2008-10-09T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "The do_splice_from function in fs/splice.c in the Linux kernel before 2.6.27 does not reject file descriptors that have the O_APPEND flag set, which allows local users to bypass append mode and make arbitrary changes to other locations in the file."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-09-28T12:57:01.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"name": "35390",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/35390"
},
{
"name": "32998",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32998"
},
{
"name": "[oss-security] 20081013 CVE request: kernel: don\u0027t allow splice() to files opened with O_APPEND",
"tags": [
"mailing-list",
"x_refsource_MLIST"
],
"url": "http://www.openwall.com/lists/oss-security/2008/10/13/1"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=466707"
},
{
"name": "MDVSA-2008:224",
"tags": [
"vendor-advisory",
"x_refsource_MANDRIVA"
],
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:224"
},
{
"name": "oval:org.mitre.oval:def:11142",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11142"
},
{
"name": "linux-kernel-dosplicefrom-security-bypass(45954)",
"tags": [
"vdb-entry",
"x_refsource_XF"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45954"
},
{
"name": "31903",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/31903"
},
{
"name": "RHSA-2009:0009",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "http://www.redhat.com/support/errata/RHSA-2009-0009.html"
},
{
"name": "SUSE-SA:2009:030",
"tags": [
"vendor-advisory",
"x_refsource_SUSE"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html"
},
{
"name": "FEDORA-2008-8929",
"tags": [
"vendor-advisory",
"x_refsource_FEDORA"
],
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00693.html"
},
{
"name": "[oss-security] 20081014 Re: CVE request: kernel: don\u0027t allow splice() to files opened with O_APPEND",
"tags": [
"mailing-list",
"x_refsource_MLIST"
],
"url": "http://www.openwall.com/lists/oss-security/2008/10/14/5"
},
{
"name": "33586",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33586"
},
{
"name": "DSA-1687",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN"
],
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.26.y.git%3Ba=commit%3Bh=efc968d450e013049a662d22727cf132618dcb2f"
},
{
"name": "32918",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32918"
},
{
"name": "USN-679-1",
"tags": [
"vendor-advisory",
"x_refsource_UBUNTU"
],
"url": "http://www.ubuntu.com/usn/usn-679-1"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27"
},
{
"name": "33180",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33180"
},
{
"name": "RHSA-2008:1017",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "http://www.redhat.com/support/errata/RHSA-2008-1017.html"
},
{
"name": "32386",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32386"
},
{
"name": "FEDORA-2008-8980",
"tags": [
"vendor-advisory",
"x_refsource_FEDORA"
],
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00689.html"
},
{
"name": "DSA-1681",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN"
],
"url": "http://www.debian.org/security/2008/dsa-1681"
},
{
"name": "33182",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33182"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2008-4554",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "The do_splice_from function in fs/splice.c in the Linux kernel before 2.6.27 does not reject file descriptors that have the O_APPEND flag set, which allows local users to bypass append mode and make arbitrary changes to other locations in the file."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "35390",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/35390"
},
{
"name": "32998",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/32998"
},
{
"name": "[oss-security] 20081013 CVE request: kernel: don\u0027t allow splice() to files opened with O_APPEND",
"refsource": "MLIST",
"url": "http://www.openwall.com/lists/oss-security/2008/10/13/1"
},
{
"name": "https://bugzilla.redhat.com/show_bug.cgi?id=466707",
"refsource": "MISC",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=466707"
},
{
"name": "MDVSA-2008:224",
"refsource": "MANDRIVA",
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:224"
},
{
"name": "oval:org.mitre.oval:def:11142",
"refsource": "OVAL",
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11142"
},
{
"name": "linux-kernel-dosplicefrom-security-bypass(45954)",
"refsource": "XF",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45954"
},
{
"name": "31903",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/31903"
},
{
"name": "RHSA-2009:0009",
"refsource": "REDHAT",
"url": "http://www.redhat.com/support/errata/RHSA-2009-0009.html"
},
{
"name": "SUSE-SA:2009:030",
"refsource": "SUSE",
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html"
},
{
"name": "FEDORA-2008-8929",
"refsource": "FEDORA",
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00693.html"
},
{
"name": "[oss-security] 20081014 Re: CVE request: kernel: don\u0027t allow splice() to files opened with O_APPEND",
"refsource": "MLIST",
"url": "http://www.openwall.com/lists/oss-security/2008/10/14/5"
},
{
"name": "33586",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33586"
},
{
"name": "DSA-1687",
"refsource": "DEBIAN",
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"name": "http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.26.y.git;a=commit;h=efc968d450e013049a662d22727cf132618dcb2f",
"refsource": "CONFIRM",
"url": "http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.26.y.git;a=commit;h=efc968d450e013049a662d22727cf132618dcb2f"
},
{
"name": "32918",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/32918"
},
{
"name": "USN-679-1",
"refsource": "UBUNTU",
"url": "http://www.ubuntu.com/usn/usn-679-1"
},
{
"name": "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27",
"refsource": "CONFIRM",
"url": "http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27"
},
{
"name": "33180",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33180"
},
{
"name": "RHSA-2008:1017",
"refsource": "REDHAT",
"url": "http://www.redhat.com/support/errata/RHSA-2008-1017.html"
},
{
"name": "32386",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/32386"
},
{
"name": "FEDORA-2008-8980",
"refsource": "FEDORA",
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00689.html"
},
{
"name": "DSA-1681",
"refsource": "DEBIAN",
"url": "http://www.debian.org/security/2008/dsa-1681"
},
{
"name": "33182",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33182"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2008-4554",
"datePublished": "2008-10-15T19:00:00.000Z",
"dateReserved": "2008-10-14T00:00:00.000Z",
"dateUpdated": "2024-08-07T10:17:09.869Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2008-4576 (GCVE-0-2008-4576)
Vulnerability from cvelistv5 – Published: 2008-10-15 19:00 – Updated: 2024-08-07 10:24
VLAI
EPSS
VEX
Summary
sctp in Linux kernel before 2.6.25.18 allows remote attackers to cause a denial of service (OOPS) via an INIT-ACK that states the peer does not support AUTH, which causes the sctp_process_init function to clean up active transports and triggers the OOPS when the T1-Init timer expires.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
25 references
Date Public
2008-10-06 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-07T10:24:20.645Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "32998",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32998"
},
{
"name": "SUSE-SA:2008:052",
"tags": [
"vendor-advisory",
"x_refsource_SUSE",
"x_transferred"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00008.html"
},
{
"name": "[oss-security] 20081008 CVE request: kernel: sctp: Fix oops when INIT-ACK indicates that peer doesn\u0027t support AUTH",
"tags": [
"mailing-list",
"x_refsource_MLIST",
"x_transferred"
],
"url": "http://permalink.gmane.org/gmane.comp.security.oss.general/1039"
},
{
"name": "RHSA-2009:0009",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT",
"x_transferred"
],
"url": "http://www.redhat.com/support/errata/RHSA-2009-0009.html"
},
{
"name": "SUSE-SA:2008:053",
"tags": [
"vendor-advisory",
"x_refsource_SUSE",
"x_transferred"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00010.html"
},
{
"name": "FEDORA-2008-8929",
"tags": [
"vendor-advisory",
"x_refsource_FEDORA",
"x_transferred"
],
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00693.html"
},
{
"name": "31634",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/31634"
},
{
"name": "33586",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33586"
},
{
"name": "DSA-1687",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN",
"x_transferred"
],
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"name": "oval:org.mitre.oval:def:9822",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL",
"x_transferred"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9822"
},
{
"name": "32918",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32918"
},
{
"name": "USN-679-1",
"tags": [
"vendor-advisory",
"x_refsource_UBUNTU",
"x_transferred"
],
"url": "http://www.ubuntu.com/usn/usn-679-1"
},
{
"name": "linux-kernel-sctp-initack-dos(45773)",
"tags": [
"vdb-entry",
"x_refsource_XF",
"x_transferred"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45773"
},
{
"name": "32759",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32759"
},
{
"name": "33180",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33180"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.18"
},
{
"name": "[linux-kernel] 20081006 [patch 58/71] sctp: Fix oops when INIT-ACK indicates that peer doesnt support AUTH",
"tags": [
"mailing-list",
"x_refsource_MLIST",
"x_transferred"
],
"url": "http://www.gossamer-threads.com/lists/linux/kernel/981012?page=last"
},
{
"name": "32370",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32370"
},
{
"name": "RHSA-2008:1017",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT",
"x_transferred"
],
"url": "http://www.redhat.com/support/errata/RHSA-2008-1017.html"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.27-rc6-git6.log"
},
{
"name": "32386",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32386"
},
{
"name": "FEDORA-2008-8980",
"tags": [
"vendor-advisory",
"x_refsource_FEDORA",
"x_transferred"
],
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00689.html"
},
{
"name": "SUSE-SR:2008:025",
"tags": [
"vendor-advisory",
"x_refsource_SUSE",
"x_transferred"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html"
},
{
"name": "DSA-1681",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN",
"x_transferred"
],
"url": "http://www.debian.org/security/2008/dsa-1681"
},
{
"name": "33182",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33182"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2008-10-06T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "sctp in Linux kernel before 2.6.25.18 allows remote attackers to cause a denial of service (OOPS) via an INIT-ACK that states the peer does not support AUTH, which causes the sctp_process_init function to clean up active transports and triggers the OOPS when the T1-Init timer expires."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-09-28T12:57:01.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"name": "32998",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32998"
},
{
"name": "SUSE-SA:2008:052",
"tags": [
"vendor-advisory",
"x_refsource_SUSE"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00008.html"
},
{
"name": "[oss-security] 20081008 CVE request: kernel: sctp: Fix oops when INIT-ACK indicates that peer doesn\u0027t support AUTH",
"tags": [
"mailing-list",
"x_refsource_MLIST"
],
"url": "http://permalink.gmane.org/gmane.comp.security.oss.general/1039"
},
{
"name": "RHSA-2009:0009",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "http://www.redhat.com/support/errata/RHSA-2009-0009.html"
},
{
"name": "SUSE-SA:2008:053",
"tags": [
"vendor-advisory",
"x_refsource_SUSE"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00010.html"
},
{
"name": "FEDORA-2008-8929",
"tags": [
"vendor-advisory",
"x_refsource_FEDORA"
],
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00693.html"
},
{
"name": "31634",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/31634"
},
{
"name": "33586",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33586"
},
{
"name": "DSA-1687",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN"
],
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"name": "oval:org.mitre.oval:def:9822",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9822"
},
{
"name": "32918",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32918"
},
{
"name": "USN-679-1",
"tags": [
"vendor-advisory",
"x_refsource_UBUNTU"
],
"url": "http://www.ubuntu.com/usn/usn-679-1"
},
{
"name": "linux-kernel-sctp-initack-dos(45773)",
"tags": [
"vdb-entry",
"x_refsource_XF"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45773"
},
{
"name": "32759",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32759"
},
{
"name": "33180",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33180"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.18"
},
{
"name": "[linux-kernel] 20081006 [patch 58/71] sctp: Fix oops when INIT-ACK indicates that peer doesnt support AUTH",
"tags": [
"mailing-list",
"x_refsource_MLIST"
],
"url": "http://www.gossamer-threads.com/lists/linux/kernel/981012?page=last"
},
{
"name": "32370",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32370"
},
{
"name": "RHSA-2008:1017",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "http://www.redhat.com/support/errata/RHSA-2008-1017.html"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.27-rc6-git6.log"
},
{
"name": "32386",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32386"
},
{
"name": "FEDORA-2008-8980",
"tags": [
"vendor-advisory",
"x_refsource_FEDORA"
],
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00689.html"
},
{
"name": "SUSE-SR:2008:025",
"tags": [
"vendor-advisory",
"x_refsource_SUSE"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html"
},
{
"name": "DSA-1681",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN"
],
"url": "http://www.debian.org/security/2008/dsa-1681"
},
{
"name": "33182",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33182"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2008-4576",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "sctp in Linux kernel before 2.6.25.18 allows remote attackers to cause a denial of service (OOPS) via an INIT-ACK that states the peer does not support AUTH, which causes the sctp_process_init function to clean up active transports and triggers the OOPS when the T1-Init timer expires."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "32998",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/32998"
},
{
"name": "SUSE-SA:2008:052",
"refsource": "SUSE",
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00008.html"
},
{
"name": "[oss-security] 20081008 CVE request: kernel: sctp: Fix oops when INIT-ACK indicates that peer doesn\u0027t support AUTH",
"refsource": "MLIST",
"url": "http://permalink.gmane.org/gmane.comp.security.oss.general/1039"
},
{
"name": "RHSA-2009:0009",
"refsource": "REDHAT",
"url": "http://www.redhat.com/support/errata/RHSA-2009-0009.html"
},
{
"name": "SUSE-SA:2008:053",
"refsource": "SUSE",
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00010.html"
},
{
"name": "FEDORA-2008-8929",
"refsource": "FEDORA",
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00693.html"
},
{
"name": "31634",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/31634"
},
{
"name": "33586",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33586"
},
{
"name": "DSA-1687",
"refsource": "DEBIAN",
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"name": "oval:org.mitre.oval:def:9822",
"refsource": "OVAL",
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9822"
},
{
"name": "32918",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/32918"
},
{
"name": "USN-679-1",
"refsource": "UBUNTU",
"url": "http://www.ubuntu.com/usn/usn-679-1"
},
{
"name": "linux-kernel-sctp-initack-dos(45773)",
"refsource": "XF",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45773"
},
{
"name": "32759",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/32759"
},
{
"name": "33180",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33180"
},
{
"name": "http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.18",
"refsource": "CONFIRM",
"url": "http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.18"
},
{
"name": "[linux-kernel] 20081006 [patch 58/71] sctp: Fix oops when INIT-ACK indicates that peer doesnt support AUTH",
"refsource": "MLIST",
"url": "http://www.gossamer-threads.com/lists/linux/kernel/981012?page=last"
},
{
"name": "32370",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/32370"
},
{
"name": "RHSA-2008:1017",
"refsource": "REDHAT",
"url": "http://www.redhat.com/support/errata/RHSA-2008-1017.html"
},
{
"name": "http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.27-rc6-git6.log",
"refsource": "CONFIRM",
"url": "http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.27-rc6-git6.log"
},
{
"name": "32386",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/32386"
},
{
"name": "FEDORA-2008-8980",
"refsource": "FEDORA",
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00689.html"
},
{
"name": "SUSE-SR:2008:025",
"refsource": "SUSE",
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html"
},
{
"name": "DSA-1681",
"refsource": "DEBIAN",
"url": "http://www.debian.org/security/2008/dsa-1681"
},
{
"name": "33182",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33182"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2008-4576",
"datePublished": "2008-10-15T19:00:00.000Z",
"dateReserved": "2008-10-15T00:00:00.000Z",
"dateUpdated": "2024-08-07T10:24:20.645Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2008-4933 (GCVE-0-2008-4933)
Vulnerability from cvelistv5 – Published: 2008-11-05 14:51 – Updated: 2024-08-07 10:31
VLAI
EPSS
VEX
Summary
Buffer overflow in the hfsplus_find_cat function in fs/hfsplus/catalog.c in the Linux kernel before 2.6.28-rc1 allows attackers to cause a denial of service (memory corruption or system crash) via an hfsplus filesystem image with an invalid catalog namelength field, related to the hfsplus_cat_build_key_uni function.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
22 references
Date Public
2008-10-23 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-07T10:31:28.327Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "32998",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32998"
},
{
"name": "MDVSA-2008:234",
"tags": [
"vendor-advisory",
"x_refsource_MANDRIVA",
"x_transferred"
],
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:234"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git%3Ba=commit%3Bh=efc7ffcb4237f8cb9938909041c4ed38f6e1bf40"
},
{
"name": "33641",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33641"
},
{
"name": "linux-kernel-hfsplusfindcat-bo(46405)",
"tags": [
"vdb-entry",
"x_refsource_XF",
"x_transferred"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46405"
},
{
"name": "32093",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/32093"
},
{
"name": "RHSA-2009:0014",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT",
"x_transferred"
],
"url": "http://www.redhat.com/support/errata/RHSA-2009-0014.html"
},
{
"name": "33556",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33556"
},
{
"name": "DSA-1687",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN",
"x_transferred"
],
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"name": "RHSA-2009:0264",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT",
"x_transferred"
],
"url": "http://rhn.redhat.com/errata/RHSA-2009-0264.html"
},
{
"name": "32918",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32918"
},
{
"name": "33858",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33858"
},
{
"name": "USN-679-1",
"tags": [
"vendor-advisory",
"x_refsource_UBUNTU",
"x_transferred"
],
"url": "http://www.ubuntu.com/usn/usn-679-1"
},
{
"name": "oval:org.mitre.oval:def:11061",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL",
"x_transferred"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11061"
},
{
"name": "[oss-security] 20081103 CVE requests: kernel: hfsplus-related bugs",
"tags": [
"mailing-list",
"x_refsource_MLIST",
"x_transferred"
],
"url": "http://www.openwall.com/lists/oss-security/2008/11/03/2"
},
{
"name": "32510",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32510"
},
{
"name": "33180",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33180"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.28-rc1"
},
{
"name": "33704",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33704"
},
{
"name": "DSA-1681",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN",
"x_transferred"
],
"url": "http://www.debian.org/security/2008/dsa-1681"
},
{
"name": "SUSE-SA:2009:008",
"tags": [
"vendor-advisory",
"x_refsource_SUSE",
"x_transferred"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00010.html"
},
{
"name": "SUSE-SA:2009:004",
"tags": [
"vendor-advisory",
"x_refsource_SUSE",
"x_transferred"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00006.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2008-10-23T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Buffer overflow in the hfsplus_find_cat function in fs/hfsplus/catalog.c in the Linux kernel before 2.6.28-rc1 allows attackers to cause a denial of service (memory corruption or system crash) via an hfsplus filesystem image with an invalid catalog namelength field, related to the hfsplus_cat_build_key_uni function."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-09-28T12:57:01.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"name": "32998",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32998"
},
{
"name": "MDVSA-2008:234",
"tags": [
"vendor-advisory",
"x_refsource_MANDRIVA"
],
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:234"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git%3Ba=commit%3Bh=efc7ffcb4237f8cb9938909041c4ed38f6e1bf40"
},
{
"name": "33641",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33641"
},
{
"name": "linux-kernel-hfsplusfindcat-bo(46405)",
"tags": [
"vdb-entry",
"x_refsource_XF"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46405"
},
{
"name": "32093",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/32093"
},
{
"name": "RHSA-2009:0014",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "http://www.redhat.com/support/errata/RHSA-2009-0014.html"
},
{
"name": "33556",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33556"
},
{
"name": "DSA-1687",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN"
],
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"name": "RHSA-2009:0264",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "http://rhn.redhat.com/errata/RHSA-2009-0264.html"
},
{
"name": "32918",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32918"
},
{
"name": "33858",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33858"
},
{
"name": "USN-679-1",
"tags": [
"vendor-advisory",
"x_refsource_UBUNTU"
],
"url": "http://www.ubuntu.com/usn/usn-679-1"
},
{
"name": "oval:org.mitre.oval:def:11061",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11061"
},
{
"name": "[oss-security] 20081103 CVE requests: kernel: hfsplus-related bugs",
"tags": [
"mailing-list",
"x_refsource_MLIST"
],
"url": "http://www.openwall.com/lists/oss-security/2008/11/03/2"
},
{
"name": "32510",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32510"
},
{
"name": "33180",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33180"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.28-rc1"
},
{
"name": "33704",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33704"
},
{
"name": "DSA-1681",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN"
],
"url": "http://www.debian.org/security/2008/dsa-1681"
},
{
"name": "SUSE-SA:2009:008",
"tags": [
"vendor-advisory",
"x_refsource_SUSE"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00010.html"
},
{
"name": "SUSE-SA:2009:004",
"tags": [
"vendor-advisory",
"x_refsource_SUSE"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00006.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2008-4933",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Buffer overflow in the hfsplus_find_cat function in fs/hfsplus/catalog.c in the Linux kernel before 2.6.28-rc1 allows attackers to cause a denial of service (memory corruption or system crash) via an hfsplus filesystem image with an invalid catalog namelength field, related to the hfsplus_cat_build_key_uni function."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "32998",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/32998"
},
{
"name": "MDVSA-2008:234",
"refsource": "MANDRIVA",
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:234"
},
{
"name": "http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git;a=commit;h=efc7ffcb4237f8cb9938909041c4ed38f6e1bf40",
"refsource": "CONFIRM",
"url": "http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git;a=commit;h=efc7ffcb4237f8cb9938909041c4ed38f6e1bf40"
},
{
"name": "33641",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33641"
},
{
"name": "linux-kernel-hfsplusfindcat-bo(46405)",
"refsource": "XF",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46405"
},
{
"name": "32093",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/32093"
},
{
"name": "RHSA-2009:0014",
"refsource": "REDHAT",
"url": "http://www.redhat.com/support/errata/RHSA-2009-0014.html"
},
{
"name": "33556",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33556"
},
{
"name": "DSA-1687",
"refsource": "DEBIAN",
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"name": "RHSA-2009:0264",
"refsource": "REDHAT",
"url": "http://rhn.redhat.com/errata/RHSA-2009-0264.html"
},
{
"name": "32918",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/32918"
},
{
"name": "33858",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33858"
},
{
"name": "USN-679-1",
"refsource": "UBUNTU",
"url": "http://www.ubuntu.com/usn/usn-679-1"
},
{
"name": "oval:org.mitre.oval:def:11061",
"refsource": "OVAL",
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11061"
},
{
"name": "[oss-security] 20081103 CVE requests: kernel: hfsplus-related bugs",
"refsource": "MLIST",
"url": "http://www.openwall.com/lists/oss-security/2008/11/03/2"
},
{
"name": "32510",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/32510"
},
{
"name": "33180",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33180"
},
{
"name": "http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.28-rc1",
"refsource": "CONFIRM",
"url": "http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.28-rc1"
},
{
"name": "33704",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33704"
},
{
"name": "DSA-1681",
"refsource": "DEBIAN",
"url": "http://www.debian.org/security/2008/dsa-1681"
},
{
"name": "SUSE-SA:2009:008",
"refsource": "SUSE",
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00010.html"
},
{
"name": "SUSE-SA:2009:004",
"refsource": "SUSE",
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00006.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2008-4933",
"datePublished": "2008-11-05T14:51:00.000Z",
"dateReserved": "2008-11-05T00:00:00.000Z",
"dateUpdated": "2024-08-07T10:31:28.327Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2008-4934 (GCVE-0-2008-4934)
Vulnerability from cvelistv5 – Published: 2008-11-05 14:51 – Updated: 2024-08-07 10:31
VLAI
EPSS
VEX
Summary
The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (system crash) via a crafted hfsplus filesystem image.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
18 references
Date Public
2008-10-23 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-07T10:31:28.173Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "32998",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32998"
},
{
"name": "MDVSA-2008:234",
"tags": [
"vendor-advisory",
"x_refsource_MANDRIVA",
"x_transferred"
],
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:234"
},
{
"name": "linux-kernel-hfsplus-dos(46327)",
"tags": [
"vdb-entry",
"x_refsource_XF",
"x_transferred"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46327"
},
{
"name": "RHSA-2009:0014",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT",
"x_transferred"
],
"url": "http://www.redhat.com/support/errata/RHSA-2009-0014.html"
},
{
"name": "33556",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33556"
},
{
"name": "DSA-1687",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN",
"x_transferred"
],
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"name": "RHSA-2009:0264",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT",
"x_transferred"
],
"url": "http://rhn.redhat.com/errata/RHSA-2009-0264.html"
},
{
"name": "32918",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32918"
},
{
"name": "33858",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33858"
},
{
"name": "USN-679-1",
"tags": [
"vendor-advisory",
"x_refsource_UBUNTU",
"x_transferred"
],
"url": "http://www.ubuntu.com/usn/usn-679-1"
},
{
"name": "[oss-security] 20081103 CVE requests: kernel: hfsplus-related bugs",
"tags": [
"mailing-list",
"x_refsource_MLIST",
"x_transferred"
],
"url": "http://www.openwall.com/lists/oss-security/2008/11/03/2"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git%3Ba=commit%3Bh=649f1ee6c705aab644035a7998d7b574193a598a"
},
{
"name": "32510",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32510"
},
{
"name": "33180",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33180"
},
{
"name": "oval:org.mitre.oval:def:11635",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL",
"x_transferred"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11635"
},
{
"name": "32096",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/32096"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.28-rc1"
},
{
"name": "DSA-1681",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN",
"x_transferred"
],
"url": "http://www.debian.org/security/2008/dsa-1681"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2008-10-23T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (system crash) via a crafted hfsplus filesystem image."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-09-28T12:57:01.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"name": "32998",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32998"
},
{
"name": "MDVSA-2008:234",
"tags": [
"vendor-advisory",
"x_refsource_MANDRIVA"
],
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:234"
},
{
"name": "linux-kernel-hfsplus-dos(46327)",
"tags": [
"vdb-entry",
"x_refsource_XF"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46327"
},
{
"name": "RHSA-2009:0014",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "http://www.redhat.com/support/errata/RHSA-2009-0014.html"
},
{
"name": "33556",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33556"
},
{
"name": "DSA-1687",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN"
],
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"name": "RHSA-2009:0264",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "http://rhn.redhat.com/errata/RHSA-2009-0264.html"
},
{
"name": "32918",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32918"
},
{
"name": "33858",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33858"
},
{
"name": "USN-679-1",
"tags": [
"vendor-advisory",
"x_refsource_UBUNTU"
],
"url": "http://www.ubuntu.com/usn/usn-679-1"
},
{
"name": "[oss-security] 20081103 CVE requests: kernel: hfsplus-related bugs",
"tags": [
"mailing-list",
"x_refsource_MLIST"
],
"url": "http://www.openwall.com/lists/oss-security/2008/11/03/2"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git%3Ba=commit%3Bh=649f1ee6c705aab644035a7998d7b574193a598a"
},
{
"name": "32510",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32510"
},
{
"name": "33180",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33180"
},
{
"name": "oval:org.mitre.oval:def:11635",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11635"
},
{
"name": "32096",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/32096"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.28-rc1"
},
{
"name": "DSA-1681",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN"
],
"url": "http://www.debian.org/security/2008/dsa-1681"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2008-4934",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (system crash) via a crafted hfsplus filesystem image."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "32998",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/32998"
},
{
"name": "MDVSA-2008:234",
"refsource": "MANDRIVA",
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:234"
},
{
"name": "linux-kernel-hfsplus-dos(46327)",
"refsource": "XF",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46327"
},
{
"name": "RHSA-2009:0014",
"refsource": "REDHAT",
"url": "http://www.redhat.com/support/errata/RHSA-2009-0014.html"
},
{
"name": "33556",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33556"
},
{
"name": "DSA-1687",
"refsource": "DEBIAN",
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"name": "RHSA-2009:0264",
"refsource": "REDHAT",
"url": "http://rhn.redhat.com/errata/RHSA-2009-0264.html"
},
{
"name": "32918",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/32918"
},
{
"name": "33858",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33858"
},
{
"name": "USN-679-1",
"refsource": "UBUNTU",
"url": "http://www.ubuntu.com/usn/usn-679-1"
},
{
"name": "[oss-security] 20081103 CVE requests: kernel: hfsplus-related bugs",
"refsource": "MLIST",
"url": "http://www.openwall.com/lists/oss-security/2008/11/03/2"
},
{
"name": "http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git;a=commit;h=649f1ee6c705aab644035a7998d7b574193a598a",
"refsource": "CONFIRM",
"url": "http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git;a=commit;h=649f1ee6c705aab644035a7998d7b574193a598a"
},
{
"name": "32510",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/32510"
},
{
"name": "33180",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33180"
},
{
"name": "oval:org.mitre.oval:def:11635",
"refsource": "OVAL",
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11635"
},
{
"name": "32096",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/32096"
},
{
"name": "http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.28-rc1",
"refsource": "CONFIRM",
"url": "http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.28-rc1"
},
{
"name": "DSA-1681",
"refsource": "DEBIAN",
"url": "http://www.debian.org/security/2008/dsa-1681"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2008-4934",
"datePublished": "2008-11-05T14:51:00.000Z",
"dateReserved": "2008-11-05T00:00:00.000Z",
"dateUpdated": "2024-08-07T10:31:28.173Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2008-5025 (GCVE-0-2008-5025)
Vulnerability from cvelistv5 – Published: 2008-11-17 23:00 – Updated: 2024-08-07 10:40
VLAI
EPSS
VEX
Summary
Stack-based buffer overflow in the hfs_cat_find_brec function in fs/hfs/catalog.c in the Linux kernel before 2.6.28-rc1 allows attackers to cause a denial of service (memory corruption or system crash) via an hfs filesystem image with an invalid catalog namelength field, a related issue to CVE-2008-4933.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
29 references
Date Public
2008-10-23 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-07T10:40:16.979Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "32998",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32998"
},
{
"name": "[oss-security] 20081110 Re: CVE requests: kernel: hfsplus-related bugs",
"tags": [
"mailing-list",
"x_refsource_MLIST",
"x_transferred"
],
"url": "http://openwall.com/lists/oss-security/2008/11/10/6"
},
{
"name": "[oss-security] 20081111 Re: CVE requests: kernel: hfsplus-related bugs",
"tags": [
"mailing-list",
"x_refsource_MLIST",
"x_transferred"
],
"url": "http://openwall.com/lists/oss-security/2008/11/11/12"
},
{
"name": "[oss-security] 20081110 Re: CVE requests: kernel: hfsplus-related bugs",
"tags": [
"mailing-list",
"x_refsource_MLIST",
"x_transferred"
],
"url": "http://openwall.com/lists/oss-security/2008/11/10/1"
},
{
"name": "MDVSA-2008:246",
"tags": [
"vendor-advisory",
"x_refsource_MANDRIVA",
"x_transferred"
],
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:246"
},
{
"name": "33641",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33641"
},
{
"name": "[oss-security] 20081111 Re: CVE requests: kernel: hfsplus-related bugs",
"tags": [
"mailing-list",
"x_refsource_MLIST",
"x_transferred"
],
"url": "http://openwall.com/lists/oss-security/2008/11/11/1"
},
{
"name": "32719",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32719"
},
{
"name": "RHSA-2009:0014",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT",
"x_transferred"
],
"url": "http://www.redhat.com/support/errata/RHSA-2009-0014.html"
},
{
"name": "[oss-security] 20081110 Re: CVE requests: kernel: hfsplus-related bugs",
"tags": [
"mailing-list",
"x_refsource_MLIST",
"x_transferred"
],
"url": "http://openwall.com/lists/oss-security/2008/11/10/7"
},
{
"name": "33556",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33556"
},
{
"name": "DSA-1687",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN",
"x_transferred"
],
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"name": "RHSA-2009:0264",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT",
"x_transferred"
],
"url": "http://rhn.redhat.com/errata/RHSA-2009-0264.html"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=470769"
},
{
"name": "32918",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32918"
},
{
"name": "33858",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33858"
},
{
"name": "USN-679-1",
"tags": [
"vendor-advisory",
"x_refsource_UBUNTU",
"x_transferred"
],
"url": "http://www.ubuntu.com/usn/usn-679-1"
},
{
"name": "49863",
"tags": [
"vdb-entry",
"x_refsource_OSVDB",
"x_transferred"
],
"url": "http://osvdb.org/49863"
},
{
"name": "[oss-security] 20081110 Re: CVE requests: kernel: hfsplus-related bugs",
"tags": [
"mailing-list",
"x_refsource_MLIST",
"x_transferred"
],
"url": "http://openwall.com/lists/oss-security/2008/11/10/3"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git%3Ba=commit%3Bh=d38b7aa7fc3371b52d036748028db50b585ade2e"
},
{
"name": "33180",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33180"
},
{
"name": "1021230",
"tags": [
"vdb-entry",
"x_refsource_SECTRACK",
"x_transferred"
],
"url": "http://www.securitytracker.com/id?1021230"
},
{
"name": "32289",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/32289"
},
{
"name": "linux-kernel-hfscatfindbrec-bo(46605)",
"tags": [
"vdb-entry",
"x_refsource_XF",
"x_transferred"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46605"
},
{
"name": "oval:org.mitre.oval:def:10470",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL",
"x_transferred"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10470"
},
{
"name": "33704",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33704"
},
{
"name": "DSA-1681",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN",
"x_transferred"
],
"url": "http://www.debian.org/security/2008/dsa-1681"
},
{
"name": "SUSE-SA:2009:008",
"tags": [
"vendor-advisory",
"x_refsource_SUSE",
"x_transferred"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00010.html"
},
{
"name": "SUSE-SA:2009:004",
"tags": [
"vendor-advisory",
"x_refsource_SUSE",
"x_transferred"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00006.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2008-10-23T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Stack-based buffer overflow in the hfs_cat_find_brec function in fs/hfs/catalog.c in the Linux kernel before 2.6.28-rc1 allows attackers to cause a denial of service (memory corruption or system crash) via an hfs filesystem image with an invalid catalog namelength field, a related issue to CVE-2008-4933."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-09-28T12:57:01.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"name": "32998",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32998"
},
{
"name": "[oss-security] 20081110 Re: CVE requests: kernel: hfsplus-related bugs",
"tags": [
"mailing-list",
"x_refsource_MLIST"
],
"url": "http://openwall.com/lists/oss-security/2008/11/10/6"
},
{
"name": "[oss-security] 20081111 Re: CVE requests: kernel: hfsplus-related bugs",
"tags": [
"mailing-list",
"x_refsource_MLIST"
],
"url": "http://openwall.com/lists/oss-security/2008/11/11/12"
},
{
"name": "[oss-security] 20081110 Re: CVE requests: kernel: hfsplus-related bugs",
"tags": [
"mailing-list",
"x_refsource_MLIST"
],
"url": "http://openwall.com/lists/oss-security/2008/11/10/1"
},
{
"name": "MDVSA-2008:246",
"tags": [
"vendor-advisory",
"x_refsource_MANDRIVA"
],
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:246"
},
{
"name": "33641",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33641"
},
{
"name": "[oss-security] 20081111 Re: CVE requests: kernel: hfsplus-related bugs",
"tags": [
"mailing-list",
"x_refsource_MLIST"
],
"url": "http://openwall.com/lists/oss-security/2008/11/11/1"
},
{
"name": "32719",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32719"
},
{
"name": "RHSA-2009:0014",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "http://www.redhat.com/support/errata/RHSA-2009-0014.html"
},
{
"name": "[oss-security] 20081110 Re: CVE requests: kernel: hfsplus-related bugs",
"tags": [
"mailing-list",
"x_refsource_MLIST"
],
"url": "http://openwall.com/lists/oss-security/2008/11/10/7"
},
{
"name": "33556",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33556"
},
{
"name": "DSA-1687",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN"
],
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"name": "RHSA-2009:0264",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "http://rhn.redhat.com/errata/RHSA-2009-0264.html"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=470769"
},
{
"name": "32918",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32918"
},
{
"name": "33858",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33858"
},
{
"name": "USN-679-1",
"tags": [
"vendor-advisory",
"x_refsource_UBUNTU"
],
"url": "http://www.ubuntu.com/usn/usn-679-1"
},
{
"name": "49863",
"tags": [
"vdb-entry",
"x_refsource_OSVDB"
],
"url": "http://osvdb.org/49863"
},
{
"name": "[oss-security] 20081110 Re: CVE requests: kernel: hfsplus-related bugs",
"tags": [
"mailing-list",
"x_refsource_MLIST"
],
"url": "http://openwall.com/lists/oss-security/2008/11/10/3"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git%3Ba=commit%3Bh=d38b7aa7fc3371b52d036748028db50b585ade2e"
},
{
"name": "33180",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33180"
},
{
"name": "1021230",
"tags": [
"vdb-entry",
"x_refsource_SECTRACK"
],
"url": "http://www.securitytracker.com/id?1021230"
},
{
"name": "32289",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/32289"
},
{
"name": "linux-kernel-hfscatfindbrec-bo(46605)",
"tags": [
"vdb-entry",
"x_refsource_XF"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46605"
},
{
"name": "oval:org.mitre.oval:def:10470",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10470"
},
{
"name": "33704",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33704"
},
{
"name": "DSA-1681",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN"
],
"url": "http://www.debian.org/security/2008/dsa-1681"
},
{
"name": "SUSE-SA:2009:008",
"tags": [
"vendor-advisory",
"x_refsource_SUSE"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00010.html"
},
{
"name": "SUSE-SA:2009:004",
"tags": [
"vendor-advisory",
"x_refsource_SUSE"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00006.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2008-5025",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Stack-based buffer overflow in the hfs_cat_find_brec function in fs/hfs/catalog.c in the Linux kernel before 2.6.28-rc1 allows attackers to cause a denial of service (memory corruption or system crash) via an hfs filesystem image with an invalid catalog namelength field, a related issue to CVE-2008-4933."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "32998",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/32998"
},
{
"name": "[oss-security] 20081110 Re: CVE requests: kernel: hfsplus-related bugs",
"refsource": "MLIST",
"url": "http://openwall.com/lists/oss-security/2008/11/10/6"
},
{
"name": "[oss-security] 20081111 Re: CVE requests: kernel: hfsplus-related bugs",
"refsource": "MLIST",
"url": "http://openwall.com/lists/oss-security/2008/11/11/12"
},
{
"name": "[oss-security] 20081110 Re: CVE requests: kernel: hfsplus-related bugs",
"refsource": "MLIST",
"url": "http://openwall.com/lists/oss-security/2008/11/10/1"
},
{
"name": "MDVSA-2008:246",
"refsource": "MANDRIVA",
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:246"
},
{
"name": "33641",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33641"
},
{
"name": "[oss-security] 20081111 Re: CVE requests: kernel: hfsplus-related bugs",
"refsource": "MLIST",
"url": "http://openwall.com/lists/oss-security/2008/11/11/1"
},
{
"name": "32719",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/32719"
},
{
"name": "RHSA-2009:0014",
"refsource": "REDHAT",
"url": "http://www.redhat.com/support/errata/RHSA-2009-0014.html"
},
{
"name": "[oss-security] 20081110 Re: CVE requests: kernel: hfsplus-related bugs",
"refsource": "MLIST",
"url": "http://openwall.com/lists/oss-security/2008/11/10/7"
},
{
"name": "33556",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33556"
},
{
"name": "DSA-1687",
"refsource": "DEBIAN",
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"name": "RHSA-2009:0264",
"refsource": "REDHAT",
"url": "http://rhn.redhat.com/errata/RHSA-2009-0264.html"
},
{
"name": "https://bugzilla.redhat.com/show_bug.cgi?id=470769",
"refsource": "CONFIRM",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=470769"
},
{
"name": "32918",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/32918"
},
{
"name": "33858",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33858"
},
{
"name": "USN-679-1",
"refsource": "UBUNTU",
"url": "http://www.ubuntu.com/usn/usn-679-1"
},
{
"name": "49863",
"refsource": "OSVDB",
"url": "http://osvdb.org/49863"
},
{
"name": "[oss-security] 20081110 Re: CVE requests: kernel: hfsplus-related bugs",
"refsource": "MLIST",
"url": "http://openwall.com/lists/oss-security/2008/11/10/3"
},
{
"name": "http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git;a=commit;h=d38b7aa7fc3371b52d036748028db50b585ade2e",
"refsource": "CONFIRM",
"url": "http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git;a=commit;h=d38b7aa7fc3371b52d036748028db50b585ade2e"
},
{
"name": "33180",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33180"
},
{
"name": "1021230",
"refsource": "SECTRACK",
"url": "http://www.securitytracker.com/id?1021230"
},
{
"name": "32289",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/32289"
},
{
"name": "linux-kernel-hfscatfindbrec-bo(46605)",
"refsource": "XF",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46605"
},
{
"name": "oval:org.mitre.oval:def:10470",
"refsource": "OVAL",
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10470"
},
{
"name": "33704",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33704"
},
{
"name": "DSA-1681",
"refsource": "DEBIAN",
"url": "http://www.debian.org/security/2008/dsa-1681"
},
{
"name": "SUSE-SA:2009:008",
"refsource": "SUSE",
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00010.html"
},
{
"name": "SUSE-SA:2009:004",
"refsource": "SUSE",
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00006.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2008-5025",
"datePublished": "2008-11-17T23:00:00.000Z",
"dateReserved": "2008-11-10T00:00:00.000Z",
"dateUpdated": "2024-08-07T10:40:16.979Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2008-5029 (GCVE-0-2008-5029)
Vulnerability from cvelistv5 – Published: 2008-11-10 16:00 – Updated: 2024-08-07 10:40
VLAI
EPSS
VEX
Summary
The __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sending an SCM_RIGHTS message through a UNIX domain socket and closing file descriptors.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
36 references
Date Public
2008-11-06 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-07T10:40:17.130Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "32998",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32998"
},
{
"name": "[oss-security] 20081106 CVE request: kernel: Unix sockets kernel panic",
"tags": [
"mailing-list",
"x_refsource_MLIST",
"x_transferred"
],
"url": "http://www.openwall.com/lists/oss-security/2008/11/06/1"
},
{
"name": "MDVSA-2008:234",
"tags": [
"vendor-advisory",
"x_refsource_MANDRIVA",
"x_transferred"
],
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:234"
},
{
"name": "RHSA-2009:0225",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT",
"x_transferred"
],
"url": "http://www.redhat.com/support/errata/RHSA-2009-0225.html"
},
{
"name": "20100625 VMSA-2010-0010 ESX 3.5 third party update for Service Console kernel",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ",
"x_transferred"
],
"url": "http://www.securityfocus.com/archive/1/512019/100/0/threaded"
},
{
"name": "33641",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33641"
},
{
"name": "4573",
"tags": [
"third-party-advisory",
"x_refsource_SREASON",
"x_transferred"
],
"url": "http://securityreason.com/securityalert/4573"
},
{
"name": "33623",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33623"
},
{
"name": "RHSA-2009:0009",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT",
"x_transferred"
],
"url": "http://www.redhat.com/support/errata/RHSA-2009-0009.html"
},
{
"name": "1021292",
"tags": [
"vdb-entry",
"x_refsource_SECTRACK",
"x_transferred"
],
"url": "http://www.securitytracker.com/id?1021292"
},
{
"name": "oval:org.mitre.oval:def:9558",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL",
"x_transferred"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9558"
},
{
"name": "1021511",
"tags": [
"vdb-entry",
"x_refsource_SECTRACK",
"x_transferred"
],
"url": "http://www.securitytracker.com/id?1021511"
},
{
"name": "RHSA-2009:0014",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT",
"x_transferred"
],
"url": "http://www.redhat.com/support/errata/RHSA-2009-0014.html"
},
{
"name": "33586",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33586"
},
{
"name": "[linux-netdev] 20081106 UNIX sockets kernel panic",
"tags": [
"mailing-list",
"x_refsource_MLIST",
"x_transferred"
],
"url": "http://marc.info/?l=linux-netdev\u0026m=122593044330973\u0026w=2"
},
{
"name": "33556",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33556"
},
{
"name": "32154",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/32154"
},
{
"name": "DSA-1687",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN",
"x_transferred"
],
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"name": "32918",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/32918"
},
{
"name": "20090104 Re: Linux Kernel 2.6.18/2.6.24/2.6.20/2.6.22/2.6.21 denial of service exploit",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ",
"x_transferred"
],
"url": "http://www.securityfocus.com/archive/1/499744/100/0/threaded"
},
{
"name": "USN-679-1",
"tags": [
"vendor-advisory",
"x_refsource_UBUNTU",
"x_transferred"
],
"url": "http://www.ubuntu.com/usn/usn-679-1"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.36.9"
},
{
"name": "linux-kernel-scmdestroy-dos(46538)",
"tags": [
"vdb-entry",
"x_refsource_XF",
"x_transferred"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46538"
},
{
"name": "33180",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33180"
},
{
"name": "RHSA-2009:1550",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT",
"x_transferred"
],
"url": "https://rhn.redhat.com/errata/RHSA-2009-1550.html"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "http://darkircop.org/unix.c"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=470201"
},
{
"name": "SUSE-SA:2008:057",
"tags": [
"vendor-advisory",
"x_refsource_SUSE",
"x_transferred"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00001.html"
},
{
"name": "20090101 Linux Kernel 2.6.18/2.6.24/2.6.20/2.6.22/2.6.21 denial of service exploit",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ",
"x_transferred"
],
"url": "http://www.securityfocus.com/archive/1/499700/100/0/threaded"
},
{
"name": "33704",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA",
"x_transferred"
],
"url": "http://secunia.com/advisories/33704"
},
{
"name": "DSA-1681",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN",
"x_transferred"
],
"url": "http://www.debian.org/security/2008/dsa-1681"
},
{
"name": "oval:org.mitre.oval:def:11694",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL",
"x_transferred"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11694"
},
{
"name": "20090103 Re: Linux Kernel 2.6.18/2.6.24/2.6.20/2.6.22/2.6.21 denial of service exploit",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ",
"x_transferred"
],
"url": "http://archives.neohapsis.com/archives/bugtraq/2009-01/0006.html"
},
{
"name": "33079",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/33079"
},
{
"name": "SUSE-SA:2009:008",
"tags": [
"vendor-advisory",
"x_refsource_SUSE",
"x_transferred"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00010.html"
},
{
"name": "SUSE-SA:2009:004",
"tags": [
"vendor-advisory",
"x_refsource_SUSE",
"x_transferred"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00006.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2008-11-06T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "The __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sending an SCM_RIGHTS message through a UNIX domain socket and closing file descriptors."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2018-10-11T19:57:01.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"name": "32998",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32998"
},
{
"name": "[oss-security] 20081106 CVE request: kernel: Unix sockets kernel panic",
"tags": [
"mailing-list",
"x_refsource_MLIST"
],
"url": "http://www.openwall.com/lists/oss-security/2008/11/06/1"
},
{
"name": "MDVSA-2008:234",
"tags": [
"vendor-advisory",
"x_refsource_MANDRIVA"
],
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:234"
},
{
"name": "RHSA-2009:0225",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "http://www.redhat.com/support/errata/RHSA-2009-0225.html"
},
{
"name": "20100625 VMSA-2010-0010 ESX 3.5 third party update for Service Console kernel",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ"
],
"url": "http://www.securityfocus.com/archive/1/512019/100/0/threaded"
},
{
"name": "33641",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33641"
},
{
"name": "4573",
"tags": [
"third-party-advisory",
"x_refsource_SREASON"
],
"url": "http://securityreason.com/securityalert/4573"
},
{
"name": "33623",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33623"
},
{
"name": "RHSA-2009:0009",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "http://www.redhat.com/support/errata/RHSA-2009-0009.html"
},
{
"name": "1021292",
"tags": [
"vdb-entry",
"x_refsource_SECTRACK"
],
"url": "http://www.securitytracker.com/id?1021292"
},
{
"name": "oval:org.mitre.oval:def:9558",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9558"
},
{
"name": "1021511",
"tags": [
"vdb-entry",
"x_refsource_SECTRACK"
],
"url": "http://www.securitytracker.com/id?1021511"
},
{
"name": "RHSA-2009:0014",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "http://www.redhat.com/support/errata/RHSA-2009-0014.html"
},
{
"name": "33586",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33586"
},
{
"name": "[linux-netdev] 20081106 UNIX sockets kernel panic",
"tags": [
"mailing-list",
"x_refsource_MLIST"
],
"url": "http://marc.info/?l=linux-netdev\u0026m=122593044330973\u0026w=2"
},
{
"name": "33556",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33556"
},
{
"name": "32154",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/32154"
},
{
"name": "DSA-1687",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN"
],
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"name": "32918",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/32918"
},
{
"name": "20090104 Re: Linux Kernel 2.6.18/2.6.24/2.6.20/2.6.22/2.6.21 denial of service exploit",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ"
],
"url": "http://www.securityfocus.com/archive/1/499744/100/0/threaded"
},
{
"name": "USN-679-1",
"tags": [
"vendor-advisory",
"x_refsource_UBUNTU"
],
"url": "http://www.ubuntu.com/usn/usn-679-1"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.36.9"
},
{
"name": "linux-kernel-scmdestroy-dos(46538)",
"tags": [
"vdb-entry",
"x_refsource_XF"
],
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46538"
},
{
"name": "33180",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33180"
},
{
"name": "RHSA-2009:1550",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://rhn.redhat.com/errata/RHSA-2009-1550.html"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "http://darkircop.org/unix.c"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=470201"
},
{
"name": "SUSE-SA:2008:057",
"tags": [
"vendor-advisory",
"x_refsource_SUSE"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00001.html"
},
{
"name": "20090101 Linux Kernel 2.6.18/2.6.24/2.6.20/2.6.22/2.6.21 denial of service exploit",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ"
],
"url": "http://www.securityfocus.com/archive/1/499700/100/0/threaded"
},
{
"name": "33704",
"tags": [
"third-party-advisory",
"x_refsource_SECUNIA"
],
"url": "http://secunia.com/advisories/33704"
},
{
"name": "DSA-1681",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN"
],
"url": "http://www.debian.org/security/2008/dsa-1681"
},
{
"name": "oval:org.mitre.oval:def:11694",
"tags": [
"vdb-entry",
"signature",
"x_refsource_OVAL"
],
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11694"
},
{
"name": "20090103 Re: Linux Kernel 2.6.18/2.6.24/2.6.20/2.6.22/2.6.21 denial of service exploit",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ"
],
"url": "http://archives.neohapsis.com/archives/bugtraq/2009-01/0006.html"
},
{
"name": "33079",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/33079"
},
{
"name": "SUSE-SA:2009:008",
"tags": [
"vendor-advisory",
"x_refsource_SUSE"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00010.html"
},
{
"name": "SUSE-SA:2009:004",
"tags": [
"vendor-advisory",
"x_refsource_SUSE"
],
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00006.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2008-5029",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "The __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sending an SCM_RIGHTS message through a UNIX domain socket and closing file descriptors."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "32998",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/32998"
},
{
"name": "[oss-security] 20081106 CVE request: kernel: Unix sockets kernel panic",
"refsource": "MLIST",
"url": "http://www.openwall.com/lists/oss-security/2008/11/06/1"
},
{
"name": "MDVSA-2008:234",
"refsource": "MANDRIVA",
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:234"
},
{
"name": "RHSA-2009:0225",
"refsource": "REDHAT",
"url": "http://www.redhat.com/support/errata/RHSA-2009-0225.html"
},
{
"name": "20100625 VMSA-2010-0010 ESX 3.5 third party update for Service Console kernel",
"refsource": "BUGTRAQ",
"url": "http://www.securityfocus.com/archive/1/512019/100/0/threaded"
},
{
"name": "33641",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33641"
},
{
"name": "4573",
"refsource": "SREASON",
"url": "http://securityreason.com/securityalert/4573"
},
{
"name": "33623",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33623"
},
{
"name": "RHSA-2009:0009",
"refsource": "REDHAT",
"url": "http://www.redhat.com/support/errata/RHSA-2009-0009.html"
},
{
"name": "1021292",
"refsource": "SECTRACK",
"url": "http://www.securitytracker.com/id?1021292"
},
{
"name": "oval:org.mitre.oval:def:9558",
"refsource": "OVAL",
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9558"
},
{
"name": "1021511",
"refsource": "SECTRACK",
"url": "http://www.securitytracker.com/id?1021511"
},
{
"name": "RHSA-2009:0014",
"refsource": "REDHAT",
"url": "http://www.redhat.com/support/errata/RHSA-2009-0014.html"
},
{
"name": "33586",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33586"
},
{
"name": "[linux-netdev] 20081106 UNIX sockets kernel panic",
"refsource": "MLIST",
"url": "http://marc.info/?l=linux-netdev\u0026m=122593044330973\u0026w=2"
},
{
"name": "33556",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33556"
},
{
"name": "32154",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/32154"
},
{
"name": "DSA-1687",
"refsource": "DEBIAN",
"url": "http://www.debian.org/security/2008/dsa-1687"
},
{
"name": "32918",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/32918"
},
{
"name": "20090104 Re: Linux Kernel 2.6.18/2.6.24/2.6.20/2.6.22/2.6.21 denial of service exploit",
"refsource": "BUGTRAQ",
"url": "http://www.securityfocus.com/archive/1/499744/100/0/threaded"
},
{
"name": "USN-679-1",
"refsource": "UBUNTU",
"url": "http://www.ubuntu.com/usn/usn-679-1"
},
{
"name": "http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.36.9",
"refsource": "CONFIRM",
"url": "http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.36.9"
},
{
"name": "linux-kernel-scmdestroy-dos(46538)",
"refsource": "XF",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46538"
},
{
"name": "33180",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33180"
},
{
"name": "RHSA-2009:1550",
"refsource": "REDHAT",
"url": "https://rhn.redhat.com/errata/RHSA-2009-1550.html"
},
{
"name": "http://darkircop.org/unix.c",
"refsource": "MISC",
"url": "http://darkircop.org/unix.c"
},
{
"name": "https://bugzilla.redhat.com/show_bug.cgi?id=470201",
"refsource": "CONFIRM",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=470201"
},
{
"name": "SUSE-SA:2008:057",
"refsource": "SUSE",
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00001.html"
},
{
"name": "20090101 Linux Kernel 2.6.18/2.6.24/2.6.20/2.6.22/2.6.21 denial of service exploit",
"refsource": "BUGTRAQ",
"url": "http://www.securityfocus.com/archive/1/499700/100/0/threaded"
},
{
"name": "33704",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/33704"
},
{
"name": "DSA-1681",
"refsource": "DEBIAN",
"url": "http://www.debian.org/security/2008/dsa-1681"
},
{
"name": "oval:org.mitre.oval:def:11694",
"refsource": "OVAL",
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11694"
},
{
"name": "20090103 Re: Linux Kernel 2.6.18/2.6.24/2.6.20/2.6.22/2.6.21 denial of service exploit",
"refsource": "BUGTRAQ",
"url": "http://archives.neohapsis.com/archives/bugtraq/2009-01/0006.html"
},
{
"name": "33079",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/33079"
},
{
"name": "SUSE-SA:2009:008",
"refsource": "SUSE",
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00010.html"
},
{
"name": "SUSE-SA:2009:004",
"refsource": "SUSE",
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00006.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2008-5029",
"datePublished": "2008-11-10T16:00:00.000Z",
"dateReserved": "2008-11-10T00:00:00.000Z",
"dateUpdated": "2024-08-07T10:40:17.130Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
Loading…
Trend slope:
-
(linear fit over daily sighting counts)
Show additional events:
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…
Loading…