Professional OVAL Repository
[Eng]
[Rus]
[Sign-In]
OVAL
Search
Categories
RedCheck
About
OVAL Definitions
OVAL Items
FSTEC Data Bank Information Security Threats
NKCKI
EOL (End Of Life)
Linux Security Advisories
Mozilla Foundation Security Advisory
IBM
VMware
Cisco
Check Point Software Technologies
Apache
Solaris
FreeBSD
Development
GitHub Enterprise
Google Chrome Security Advisories
Oracle Security Advisories
Adobe Security Advisories
OpenSSL Security Advisories
Microsoft
CVE
CWE
CPE
Latest Updates
OS ROSA
ALT Linux
Astra Linux
RED OS
DSA (Debian Security Advisory) Patсh Statistics
DSA (Debian Security Advisory) Patсh Feed
DSA (Debian Security Advisory) Vulnerability Feed
DLA (Debian Security Advisory) Patсh Statistics
DLA (Debian Security Advisory) Patсh Feed
DLA (Debian Security Advisory) Vulnerability Feed
ALT Linux (Security Bulletins) Patсh Statistics
ALT Linux (Security Bulletins) Patсh Feed
ALT Linux (Security Bulletins) Vulnerability Feed
RED OS (Security Bulletins) Patсh Statistics
RED OS (Security Bulletins) Patсh Feed
RED OS (Security Bulletins) Vulnerability Feed
USN (Ubuntu Security Notice) Patсh Statistics
USN (Ubuntu Security Notice) Patсh Feed
USN (Ubuntu Security Notice) Vulnerability Feed
RHSA (RedHat Security Advisory) Patсh Statistics
RHSA (RedHat Security Advisory) Patсh Feed
RHSA (RedHat Security Advisory) Vulnerability Feed
ELSA (Oracle Linux Security Advisory) Patсh Statistics
ELSA (Oracle Linux Security Advisory) Patсh Feed
ELSA (Oracle Linux Security Advisory) Vulnerability Feed
SUSE (SUSE Security Advisories) Patсh Statistics
SUSE (SUSE Security Advisories) Patсh Feed
SUSE (SUSE Security Advisories) Vulnerability Feed
openSUSE (openSUSE Security Advisories) Patсh Statistics
openSUSE (openSUSE Security Advisories) Patсh Feed
openSUSE (openSUSE Security Advisories) Vulnerability Feed
Amazon Linux AMI (Security Bulletins) Patсh Statistics
Amazon Linux AMI (Security Bulletins) Patсh Feed
Amazon Linux AMI (Security Bulletins) Vulnerability Feed
Mageia Linux (Security Bulletins) Patсh Statistics
Mageia Linux (Security Bulletins) Patсh Feed
Mageia Linux (Security Bulletins) Vulnerability Feed
OS ROSA SX COBALT 1.0
OS ROSA DX COBALT 1.0
ROSA 7.3 (Security Advisories) Patсh Statistics
ROSA 7.3 (Security Advisories) Patсh Feed
ROSA 7.3 (Security Advisories) Vulnerability Feed
ALT Linux SPT 6.0
ALT Linux SPT 7.0
ALT 8 SP
ALT 9
Astra Linux SE 1.5
Astra Linux SE 1.6
Astra Linux SE 1.7
Astra Linux SE 1.8
RED OS Murom 7.1
RED OS Murom 7.2
IBM DB2
VMware Vulnerabilities Advisory (VMSA)
VMware vCenter Patch Advisories
VMware ESXi Patch Advisories
VMware NSX Patches
VMware NSX Vulnerabilities
VMware Photon OS 1.0 Patches
VMware Photon OS 1.0 Vulnerabilities
VMware Photon OS 2.0 Patches
VMware Photon OS 2.0 Vulnerabilities
Cisco ASA
Cisco IOS/NX-OS Advisory
Cisco NX-OS Vulnerabilities
Check Point Gaia
Apache Tomcat Advisories
Apache Tomcat Server
Apache HTTP Server
Python
Node.js
RubyGems
Qt
Microsoft Security Bulletin
Microsoft Knowledge Base Article
Microsoft SharePoint
Microsoft SharePoint Foundation 2013
Microsoft SharePoint Server 2013
Microsoft SharePoint Server 2016
About OVALdb
User manual
Pricing
Contact us
OVAL Definitions
>
OVAL Definition Details
Id
oval:com.altx-soft.nix:def:13013
[Rus]
Version
8
Class
patch
ALTXid
29628
Language
English
Severity
Critical
Title
DSA-2240-1 linux-2.6 -- privilege escalation/denial of service/information leak
Description
Multiple vulnerabilities in Linux kernel.
Family
unix
Platform
Debian GNU/kFreeBSD 6.0
Debian GNU/Linux 6.0
Product
linux-2.6
Reference
VENDOR: DSA-2240-1
VENDOR: DSA-2240-1
Id:
DSA-2240-1
Reference:
http://lists.debian.org/debian-security-announce/2011/msg00111.html
CVE: CVE-2010-3875
CVE: CVE-2010-3875
Id:
CVE-2010-3875
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3875
Comment
: The ax25_getname function in net/ax25/af_ax25.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory by reading a copy of this structure.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=649713 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc2 (CONFIRM)
[oss-security] 20101102 CVE request: kernel stack infoleaks (MLIST)
[netdev] 20101031 [PATCH 1/3] net: ax25: fix information leak to userland (MLIST)
[oss-security] 20101104 Re: CVE request: kernel stack infoleaks (MLIST)
DSA-2126 (DEBIAN)
44630 (BID)
MDVSA-2011:029 (MANDRIVA)
MDVSA-2011:051 (MANDRIVA)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fe10ae53384e48c51996941b7720ee16995cbcb7 (MISC)
CVE: CVE-2011-0695
CVE: CVE-2011-0695
Id:
CVE-2011-0695
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0695
Comment
: Race condition in the cm_work_handler function in the InfiniBand driver (drivers/infiniband/core/cma.c) in Linux kernel 2.6.x allows remote attackers to cause a denial of service (panic) by sending an InfiniBand request while other request handlers are still running, which triggers an invalid pointer dereference.
CVSSv2 Score:
5.7
Access vector:
ADJACENT_NETWORK
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:A/AC:M/Au:N/C:N/I:N/A:C
CWE:
362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'))
References:
[linux-rdma] 20110223 [PATCH 2/2] ib/cm: Bump reference count on cm_id before invoking callback (MLIST)
43693 (SECUNIA)
46839 (BID)
[linux-rdma] 20110223 [PATCH 1/2] rdma/cm: Fix crash in request handlers (MLIST)
[oss-security] 20110311 CVE-2011-0695 kernel: panic in ib_cm:cm_work_handler (MLIST)
USN-1146-1 (UBUNTU)
RHSA-2011:0927 (REDHAT)
kernel-infiniband-dos(66056) (XF)
CVE: CVE-2011-0711
CVE: CVE-2011-0711
Id:
CVE-2011-0711
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0711
Comment
: The xfs_fs_geometry function in fs/xfs/xfs_fsops.c in the Linux kernel before 2.6.38-rc6-git3 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FSGEOMETRY_V1 ioctl call.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=677260 (CONFIRM)
46417 (BID)
[oss-security] 20110216 Re: CVE request - kernel: xfs infoleak (MLIST)
[oss-security] 20110216 CVE request - kernel: xfs infoleak (MLIST)
https://patchwork.kernel.org/patch/555461/ (CONFIRM)
70950 (OSVDB)
http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.38-rc6-git3.log (CONFIRM)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3a3675b7f23f83ca8c67c9c2b6edf707fd28d1ba (MISC)
CVE: CVE-2011-0726
CVE: CVE-2011-0726
Id:
CVE-2011-0726
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0726
Comment
: The do_task_stat function in fs/proc/array.c in the Linux kernel before 2.6.39-rc1 does not perform an expected uid check, which makes it easier for local users to defeat the ASLR protection mechanism by reading the start_code and end_code fields in the /proc/#####/stat file for a process executing a PIE binary.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
20 (Improper Input Validation)
References:
[linux-kernel] 20110311 [PATCH] proc: protect mm start_code/end_code in /proc/pid/stat (MLIST)
[mm-commits] 20110314 + proc-protect-mm-start_code-end_code-in-proc-pid-stat.patch added to -mm tree (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=684569 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/v2.6.39/ChangeLog-2.6.39-rc1 (CONFIRM)
47791 (BID)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=5883f57ca0008ffc93e09cbb9847a1928e50c6f3 ()
CVE: CVE-2011-1016
CVE: CVE-2011-1016
Id:
CVE-2011-1016
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1016
Comment
: The Radeon GPU drivers in the Linux kernel before 2.6.38-rc5 do not properly validate data related to the AA resolve registers, which allows local users to write to arbitrary memory locations associated with (1) Video RAM (aka VRAM) or (2) the Graphics Translation Table (GTT) via crafted values.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
PARTIAL
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:P/A:N
CWE:
20 (Improper Input Validation)
References:
[oss-security] 20110224 CVE request: kernel: drm/radeon/kms: check AA resolve registers on r300 (MLIST)
46557 (BID)
[oss-security] 20110224 Re: CVE request: kernel: drm/radeon/kms: check AA resolve registers on r300 (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.38-rc5 (CONFIRM)
[oss-security] 20110225 Re: CVE request: kernel: drm/radeon/kms: check AA resolve registers on r300 (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=680000 (CONFIRM)
kernel-atiradeon-sec-bypass(65691) (XF)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fff1ce4dc6113b6fdc4e3a815ca5fd229408f8ef (MISC)
CVE: CVE-2011-1078
CVE: CVE-2011-1078
Id:
CVE-2011-1078
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1078
Comment
: The sco_sock_getsockopt_old function in net/bluetooth/sco.c in the Linux kernel before 2.6.39 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via the SCO_CONNINFO option.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110301 Re: CVE request: kernel: two bluetooth and one ebtables infoleaks/DoSes (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=681259 (CONFIRM)
https://github.com/torvalds/linux/commit/c4c896e1471aec3b004a693c689f60be3b17ac86 (CONFIRM)
RHSA-2012:1156 (REDHAT)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c4c896e1471aec3b004a693c689f60be3b17ac86 (MISC)
CVE: CVE-2011-1079
CVE: CVE-2011-1079
Id:
CVE-2011-1079
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1079
Comment
: The bnep_sock_ioctl function in net/bluetooth/bnep/sock.c in the Linux kernel before 2.6.39 does not ensure that a certain device field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory, or cause a denial of service (BUG and system crash), via a BNEPCONNADD command.
CVSSv2 Score:
5.4
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:C
CWE:
20 (Improper Input Validation)
References:
https://github.com/torvalds/linux/commit/43629f8f5ea32a998d06d1bb41eefa0e821ff573 (CONFIRM)
[oss-security] 20110301 Re: CVE request: kernel: two bluetooth and one ebtables infoleaks/DoSes (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=681260 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://packetstormsecurity.com/files/153799/Kernel-Live-Patch-Security-Notice-LSN-0053-1.html (MISC)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=43629f8f5ea32a998d06d1bb41eefa0e821ff573 (MISC)
CVE: CVE-2011-1080
CVE: CVE-2011-1080
Id:
CVE-2011-1080
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1080
Comment
: The do_replace function in net/bridge/netfilter/ebtables.c in the Linux kernel before 2.6.39 does not ensure that a certain name field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory by leveraging the CAP_NET_ADMIN capability to replace a table, and then reading a modprobe command line.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
20 (Improper Input Validation)
References:
[oss-security] 20110301 Re: CVE request: kernel: two bluetooth and one ebtables infoleaks/DoSes (MLIST)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=681262 (CONFIRM)
https://github.com/torvalds/linux/commit/d846f71195d57b0bbb143382647c2c6638b04c5a (CONFIRM)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d846f71195d57b0bbb143382647c2c6638b04c5a (MISC)
CVE: CVE-2011-1090
CVE: CVE-2011-1090
Id:
CVE-2011-1090
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1090
Comment
: The __nfs4_proc_set_acl function in fs/nfs/nfs4proc.c in the Linux kernel before 2.6.38 stores NFSv4 ACL data in memory that is allocated by kmalloc but not properly freed, which allows local users to cause a denial of service (panic) via a crafted attempt to set an ACL.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
399 (Resource Management Errors)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=682641 (CONFIRM)
[oss-security] 20110307 Re: CVE request - kernel: nfs4: Ensure that ACL pages sent over NFS were not allocated from the slab (MLIST)
1025336 (SECTRACK)
[oss-security] 20110307 CVE request - kernel: nfs4: Ensure that ACL pages sent over NFS were not allocated from the slab (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
SUSE-SU-2015:0812 (SUSE)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e9e3d724e2145f5039b423c290ce2b2c3d8f94bc (MISC)
CVE: CVE-2011-1160
CVE: CVE-2011-1160
Id:
CVE-2011-1160
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1160
Comment
: The tpm_open function in drivers/char/tpm/tpm.c in the Linux kernel before 2.6.39 does not initialize a certain buffer, which allows local users to obtain potentially sensitive information from kernel memory via unspecified vectors.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://github.com/torvalds/linux/commit/1309d7afbed112f0e8e90be9af975550caa0076b (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=684671 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110315 Re: CVE requests - kernel: tpm infoleaks (MLIST)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1309d7afbed112f0e8e90be9af975550caa0076b (MISC)
CVE: CVE-2011-1163
CVE: CVE-2011-1163
Id:
CVE-2011-1163
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1163
Comment
: The osf_partition function in fs/partitions/osf.c in the Linux kernel before 2.6.38 does not properly handle an invalid number of partitions, which might allow local users to obtain potentially sensitive information from kernel heap memory via vectors related to partition-table parsing.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
20 (Improper Input Validation)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=688021 (CONFIRM)
1025225 (SECTRACK)
[oss-security] 20110315 Re: CVE Request: kernel: fs/partitions: Corrupted OSF partition table can cause information disclosure (MLIST)
[oss-security] 20110315 CVE Request: kernel: fs/partitions: Corrupted OSF partition table can cause information disclosure (MLIST)
http://www.pre-cert.de/advisories/PRE-SA-2011-02.txt (MISC)
[mm-commits] 20110314 + fs-partitions-osfc-corrupted-osf-partition-table-can-cause-information-disclosure.patch added to -mm tree (MLIST)
20110317 [PRE-SA-2011-02] Information disclosure vulnerability in the OSF partition handling code of the Linux kernel (BUGTRAQ)
46878 (BID)
8189 (SREASON)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
SUSE-SU-2015:0812 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1eafbfeb7bdf59cfe173304c76188f3fd5f1fd05 (MISC)
CVE: CVE-2011-1170
CVE: CVE-2011-1170
Id:
CVE-2011-1170
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1170
Comment
: net/ipv4/netfilter/arp_tables.c in the IPv4 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[netfilter-devel] 20110310 [PATCH] ipv4: netfilter: arp_tables: fix infoleak to userspace (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=689321 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
8282 (SREASON)
8278 (SREASON)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=42eab94fff18cb1091d3501cd284d6bd6cc9c143 (MISC)
CVE: CVE-2011-1171
CVE: CVE-2011-1171
Id:
CVE-2011-1171
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1171
Comment
: net/ipv4/netfilter/ip_tables.c in the IPv4 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
[linux-kernel] 20110310 [PATCH] ipv4: netfilter: ip_tables: fix infoleak to userspace (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=689327 (CONFIRM)
8278 (SREASON)
8283 (SREASON)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=78b79876761b86653df89c48a7010b5cbd41a84a (MISC)
CVE: CVE-2011-1172
CVE: CVE-2011-1172
Id:
CVE-2011-1172
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1172
Comment
: net/ipv6/netfilter/ip6_tables.c in the IPv6 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
[linux-kernel] 20110310 [PATCH] ipv6: netfilter: ip6_tables: fix infoleak to userspace (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=689345 (CONFIRM)
8278 (SREASON)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6a8ab060779779de8aea92ce3337ca348f973f54 (MISC)
CVE: CVE-2011-1173
CVE: CVE-2011-1173
Id:
CVE-2011-1173
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1173
Comment
: The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.39 on the x86_64 platform allows remote attackers to obtain potentially sensitive information from kernel stack memory by reading uninitialized data in the ah field of an Acorn Universal Networking (AUN) packet.
CVSSv2 Score:
5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[netdev] 20110317 [PATCH] econet: 4 byte infoleak to the network (MLIST)
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=591815#c14 (MISC)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
8279 (SREASON)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=67c5c6cb8129c595f21e88254a3fc6b3b841ae8e (MISC)
CVE: CVE-2011-1180
CVE: CVE-2011-1180
Id:
CVE-2011-1180
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1180
Comment
: Multiple stack-based buffer overflows in the iriap_getvaluebyclass_indication function in net/irda/iriap.c in the Linux kernel before 2.6.39 allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging connectivity to an IrDA infrared network and sending a large integer value for a (1) name length or (2) attribute length.
CVSSv2 Score:
7.5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSSv3 Score:
9.8
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE:
787 (Out-of-bounds Write)
References:
https://github.com/torvalds/linux/commit/d370af0ef7951188daeb15bae75db7ba57c67846 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110322 Re: CVE requests - kernel: irda/decnet issues (MLIST)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d370af0ef7951188daeb15bae75db7ba57c67846 ()
CVE: CVE-2011-1182
CVE: CVE-2011-1182
Id:
CVE-2011-1182
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1182
Comment
: kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a signal sender via a sigqueueinfo system call.
CVSSv2 Score:
3.6
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:P/A:P
References:
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=690028 (CONFIRM)
https://github.com/torvalds/linux/commit/da48524eb20662618854bb3df2db01fc65f3070c (CONFIRM)
[oss-security] 20110323 Re: Linux kernel signal spoofing vulnerability (CVE request) (MLIST)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=da48524eb20662618854bb3df2db01fc65f3070c (MISC)
CVE: CVE-2011-1476
CVE: CVE-2011-1476
Id:
CVE-2011-1476
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1476
Comment
: Integer underflow in the Open Sound System (OSS) subsystem in the Linux kernel before 2.6.39 on unspecified non-x86 platforms allows local users to cause a denial of service (memory corruption) by leveraging write access to /dev/sequencer.
CVSSv2 Score:
4
Access vector:
LOCAL
Access complexity:
HIGH
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:H/Au:N/C:N/I:N/A:C
CWE:
189 (Numeric Errors)
References:
https://github.com/torvalds/linux/commit/b769f49463711205d57286e64cf535ed4daf59e9 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110325 Re: CVE request: kernel: two OSS fixes (MLIST)
SUSE-SU-2015:0812 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b769f49463711205d57286e64cf535ed4daf59e9 (MISC)
CVE: CVE-2011-1477
CVE: CVE-2011-1477
Id:
CVE-2011-1477
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1477
Comment
: Multiple array index errors in sound/oss/opl3.c in the Linux kernel before 2.6.39 allow local users to cause a denial of service (heap memory corruption) or possibly gain privileges by leveraging write access to /dev/sequencer.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
264 (Permissions, Privileges, and Access Controls)
References:
https://github.com/torvalds/linux/commit/4d00135a680727f6c3be78f8befaac009030e4df (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110325 Re: CVE request: kernel: two OSS fixes (MLIST)
SUSE-SU-2015:0812 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4d00135a680727f6c3be78f8befaac009030e4df (MISC)
CVE: CVE-2011-1478
CVE: CVE-2011-1478
Id:
CVE-2011-1478
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1478
Comment
: The napi_reuse_skb function in net/core/dev.c in the Generic Receive Offload (GRO) implementation in the Linux kernel before 2.6.38 does not reset the values of certain structure members, which might allow remote attackers to cause a denial of service (NULL pointer dereference) via a malformed VLAN frame.
CVSSv2 Score:
5.7
Access vector:
ADJACENT_NETWORK
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:A/AC:M/Au:N/C:N/I:N/A:C
CWE:
476 (NULL Pointer Dereference)
References:
http://mirror.anl.gov/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=691270 (CONFIRM)
46397 (SECUNIA)
[oss-security] 20110328 CVE-2011-1478 kernel: gro: reset dev and skb_iff on skb reuse (MLIST)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
8480 (SREASON)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6d152e23ad1a7a5b40fef1f42e017d66e6115159 (MISC)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=66c46d741e2e60f0e8b625b80edb0ab820c46d7a (MISC)
CVE: CVE-2011-1493
CVE: CVE-2011-1493
Id:
CVE-2011-1493
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1493
Comment
: Array index error in the rose_parse_national function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by composing FAC_NATIONAL_DIGIS data that specifies a large number of digipeaters, and then sending this data to a ROSE socket.
CVSSv2 Score:
7.5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE:
CWE-Other ()
References:
https://bugzilla.redhat.com/show_bug.cgi?id=770777 (CONFIRM)
https://github.com/torvalds/linux/commit/be20250c13f88375345ad99950190685eda51eb8 (CONFIRM)
[oss-security] 20110405 Re: CVE request: kernel: multiple issues in ROSE (MLIST)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
SUSE-SU-2015:0812 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=be20250c13f88375345ad99950190685eda51eb8 (MISC)
CVE: CVE-2011-1494
CVE: CVE-2011-1494
Id:
CVE-2011-1494
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1494
Comment
: Integer overflow in the _ctl_do_mpt_command function in drivers/scsi/mpt2sas/mpt2sas_ctl.c in the Linux kernel 2.6.38 and earlier might allow local users to gain privileges or cause a denial of service (memory corruption) via an ioctl call specifying a crafted value that triggers a heap-based buffer overflow.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE:
189 (Numeric Errors)
References:
[oss-security] 20110405 CVE request: kernel: two issues in mpt2sas (MLIST)
[linux-kernel] 20110405 [PATCH] drivers/scsi/mpt2sas: prevent heap overflows and unchecked reads (MLIST)
[oss-security] 20110406 Re: CVE request: kernel: two issues in mpt2sas (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=694021 (CONFIRM)
https://patchwork.kernel.org/patch/688021/ (CONFIRM)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
RHSA-2011:0833 (REDHAT)
47185 (BID)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
SUSE-SU-2015:0812 (SUSE)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
CVE: CVE-2011-1495
CVE: CVE-2011-1495
Id:
CVE-2011-1495
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1495
Comment
: drivers/scsi/mpt2sas/mpt2sas_ctl.c in the Linux kernel 2.6.38 and earlier does not validate (1) length and (2) offset values before performing memory copy operations, which might allow local users to gain privileges, cause a denial of service (memory corruption), or obtain sensitive information from kernel memory via a crafted ioctl call, related to the _ctl_do_mpt_command and _ctl_diag_read_buffer functions.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
20 (Improper Input Validation)
References:
[linux-kernel] 20110405 [PATCH] drivers/scsi/mpt2sas: prevent heap overflows and unchecked reads (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=694021 (CONFIRM)
[oss-security] 20110405 CVE request: kernel: two issues in mpt2sas (MLIST)
https://patchwork.kernel.org/patch/688021/ (CONFIRM)
[oss-security] 20110406 Re: CVE request: kernel: two issues in mpt2sas (MLIST)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
RHSA-2011:0833 (REDHAT)
47185 (BID)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
SUSE-SU-2015:0812 (SUSE)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
CVE: CVE-2011-1585
CVE: CVE-2011-1585
Id:
CVE-2011-1585
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1585
Comment
: The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not properly determine the associations between users and sessions, which allows local users to bypass CIFS share authentication by leveraging a mount of a share by a different user.
CVSSv2 Score:
3.3
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:P/A:N
CWE:
264 (Permissions, Privileges, and Access Controls)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=697394 (CONFIRM)
[oss-security] 20110415 Re: CVE Request: cifs session reuse (MLIST)
https://github.com/torvalds/linux/commit/4ff67b720c02c36e54d55b88c2931879b7db1cd2 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36 (CONFIRM)
SUSE-SU-2015:0812 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4ff67b720c02c36e54d55b88c2931879b7db1cd2 (MISC)
CVE: CVE-2011-1593
CVE: CVE-2011-1593
Id:
CVE-2011-1593
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1593
Comment
: Multiple integer overflows in the next_pidmap function in kernel/pid.c in the Linux kernel before 2.6.38.4 allow local users to cause a denial of service (system crash) via a crafted (1) getdents or (2) readdir system call.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
190 (Integer Overflow or Wraparound)
References:
[oss-security] 20110420 Re: CVE request -- kernel: proc: signedness issue in next_pidmap() (MLIST)
[linux-kernel] 20110418 Re: Kernel panic (NULL ptr deref?) in find_ge_pid()/next_pidmap() (via sys_getdents or sys_readdir) (MLIST)
44164 (SECUNIA)
https://bugzilla.redhat.com/show_bug.cgi?id=697822 (CONFIRM)
1025420 (SECTRACK)
[oss-security] 20110419 CVE request -- kernel: proc: signedness issue in next_pidmap() (MLIST)
47497 (BID)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38.4 (CONFIRM)
USN-1146-1 (UBUNTU)
RHSA-2011:0927 (REDHAT)
kernel-nextpidmap-dos(66876) (XF)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c78193e9c7bcbf25b8237ad0dec82f805c4ea69b (MISC)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d8bdc59f215e62098bc5b4256fd9928bf27053a1 (MISC)
CVE: CVE-2011-1598
CVE: CVE-2011-1598
Id:
CVE-2011-1598
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1598
Comment
: The bcm_release function in net/can/bcm.c in the Linux kernel before 2.6.39-rc6 does not properly validate a socket data structure, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted release operation.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
476 (NULL Pointer Dereference)
References:
[netdev] 20110420 Add missing socket check in can/bcm release. (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110425 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110422 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.39-rc6 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=698057 (CONFIRM)
[oss-security] 20110420 CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110420 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
47503 (BID)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c6914a6f261aca0c9f715f883a353ae7ff51fe83 (MISC)
CVE: CVE-2011-1745
CVE: CVE-2011-1745
Id:
CVE-2011-1745
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1745
Comment
: Integer overflow in the agp_generic_insert_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 allows local users to gain privileges or cause a denial of service (system crash) via a crafted AGPIOC_BIND agp_ioctl ioctl call.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE:
190 (Integer Overflow or Wraparound)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38.5 (CONFIRM)
[oss-security] 20110421 CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=698996 (CONFIRM)
[oss-security] 20110422 Re: CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
[linux-kernel] 20110414 [PATCH] char: agp: fix arbitrary kernel memory writes (MLIST)
47534 (BID)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=194b3da873fd334ef183806db751473512af29ce (MISC)
CVE: CVE-2011-1746
CVE: CVE-2011-1746
Id:
CVE-2011-1746
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1746
Comment
: Multiple integer overflows in the (1) agp_allocate_memory and (2) agp_create_user_memory functions in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 allow local users to trigger buffer overflows, and consequently cause a denial of service (system crash) or possibly have unspecified other impact, via vectors related to calls that specify a large number of memory pages.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE:
189 (Numeric Errors)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38.5 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=698998 (CONFIRM)
[oss-security] 20110421 CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
[oss-security] 20110422 Re: CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
[linux-kernel] 20110419 Re: [PATCH] char: agp: fix OOM and buffer overflow (MLIST)
[linux-kernel] 20110414 [PATCH] char: agp: fix OOM and buffer overflow (MLIST)
47535 (BID)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b522f02184b413955f3bc952e3776ce41edc6355 (MISC)
CVE: CVE-2011-1748
CVE: CVE-2011-1748
Id:
CVE-2011-1748
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1748
Comment
: The raw_release function in net/can/raw.c in the Linux kernel before 2.6.39-rc6 does not properly validate a socket data structure, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted release operation.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
476 (NULL Pointer Dereference)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.39-rc6 (CONFIRM)
[oss-security] 20110425 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=698057 (CONFIRM)
[oss-security] 20110422 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[netdev] 20110420 [PATCH v2] can: add missing socket check in can/raw release (MLIST)
47835 (BID)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=10022a6c66e199d8f61d9044543f38785713cbbd (MISC)
CVE: CVE-2011-1759
CVE: CVE-2011-1759
Id:
CVE-2011-1759
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1759
Comment
: Integer overflow in the sys_oabi_semtimedop function in arch/arm/kernel/sys_oabi-compat.c in the Linux kernel before 2.6.39 on the ARM platform, when CONFIG_OABI_COMPAT is enabled, allows local users to gain privileges or cause a denial of service (heap memory corruption) by providing a crafted argument and leveraging a race condition.
CVSSv2 Score:
6.2
Access vector:
LOCAL
Access complexity:
HIGH
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:H/Au:N/C:C/I:C/A:C
CWE:
189 (Numeric Errors)
References:
https://github.com/torvalds/linux/commit/0f22072ab50cac7983f9660d33974b45184da4f9 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110502 Re: CVE request: kernel (ARM): heap corruption in OABI semtimedop (MLIST)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0f22072ab50cac7983f9660d33974b45184da4f9 (MISC)
CVE: CVE-2011-1767
CVE: CVE-2011-1767
Id:
CVE-2011-1767
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1767
Comment
: net/ipv4/ip_gre.c in the Linux kernel before 2.6.34, when ip_gre is configured as a module, allows remote attackers to cause a denial of service (OOPS) by sending a packet during module loading.
CVSSv2 Score:
5.4
Access vector:
NETWORK
Access complexity:
HIGH
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:H/Au:N/C:N/I:N/A:C
CWE:
CWE-Other ()
References:
https://github.com/torvalds/linux/commit/c2892f02712e9516d72841d5c019ed6916329794 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=702303 (CONFIRM)
[oss-security] 20110505 Re: CVE requests - kernel network vulns (MLIST)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.34 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c2892f02712e9516d72841d5c019ed6916329794 (MISC)
CVE: CVE-2011-1770
CVE: CVE-2011-1770
Id:
CVE-2011-1770
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1770
Comment
: Integer underflow in the dccp_parse_options function (net/dccp/options.c) in the Linux kernel before 2.6.33.14 allows remote attackers to cause a denial of service via a Datagram Congestion Control Protocol (DCCP) packet with an invalid feature options length, which triggers a buffer over-read.
CVSSv2 Score:
7.8
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
7.5
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
191 (Integer Underflow (Wrap or Wraparound))
References:
FEDORA-2011-7551 (FEDORA)
https://bugzilla.redhat.com/show_bug.cgi?id=703011 (CONFIRM)
[linux-kernel] 20110506 Re: [PATCH] dccp: handle invalid feature options length (MLIST)
44932 (SECUNIA)
47769 (BID)
[linux-kernel] 20110506 [PATCH] dccp: handle invalid feature options length (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/longterm/v2.6.33/ChangeLog-2.6.33.14 (CONFIRM)
1025592 (SECTRACK)
FEDORA-2011-7823 (FEDORA)
8286 (SREASON)
CVE: CVE-2011-1776
CVE: CVE-2011-1776
Id:
CVE-2011-1776
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1776
Comment
: The is_gpt_valid function in fs/partitions/efi.c in the Linux kernel before 2.6.39 does not check the size of an Extensible Firmware Interface (EFI) GUID Partition Table (GPT) entry, which allows physically proximate attackers to cause a denial of service (heap-based buffer overflow and OOPS) or obtain sensitive information from kernel heap memory by connecting a crafted GPT storage device, a different vulnerability than CVE-2011-1577.
CVSSv2 Score:
5.6
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:C
CVSSv3 Score:
6.1
Attack vector:
PHYSICAL
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CWE:
119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
47796 (BID)
https://bugzilla.redhat.com/show_bug.cgi?id=703026 (CONFIRM)
http://www.pre-cert.de/advisories/PRE-SA-2011-04.txt (MISC)
[oss-security] 20110510 Re: CVE request: kernel: validate size of EFI GUID partition entries (MLIST)
8369 (SREASON)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fa039d5f6b126fbd65eefa05db2f67e44df8f121 (MISC)
CVE: CVE-2011-2022
CVE: CVE-2011-2022
Id:
CVE-2011-2022
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2022
Comment
: The agp_generic_remove_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 does not validate a certain start parameter, which allows local users to gain privileges or cause a denial of service (system crash) via a crafted AGPIOC_UNBIND agp_ioctl ioctl call, a different vulnerability than CVE-2011-1745.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE:
20 (Improper Input Validation)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38.5 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=698996 (CONFIRM)
[oss-security] 20110421 CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
[linux-kernel] 20110414 [PATCH] char: agp: fix arbitrary kernel memory writes (MLIST)
[oss-security] 20110422 Re: CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
47843 (BID)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=194b3da873fd334ef183806db751473512af29ce ()
Content available only for registered users!
ovaldb@altx-soft.com