Professional OVAL Repository
[Eng]
[Rus]
[Sign-In]
OVAL
Search
Categories
RedCheck
About
OVAL Definitions
OVAL Items
FSTEC Data Bank Information Security Threats
NKCKI
EOL (End Of Life)
Linux Security Advisories
Mozilla Foundation Security Advisory
IBM
VMware
Cisco
Check Point Software Technologies
Apache
Solaris
FreeBSD
Development
GitHub Enterprise
Google Chrome Security Advisories
Oracle Security Advisories
Adobe Security Advisories
OpenSSL Security Advisories
Microsoft
CVE
CWE
CPE
Latest Updates
OS ROSA
ALT Linux
Astra Linux
RED OS
DSA (Debian Security Advisory) Patсh Statistics
DSA (Debian Security Advisory) Patсh Feed
DSA (Debian Security Advisory) Vulnerability Feed
DLA (Debian Security Advisory) Patсh Statistics
DLA (Debian Security Advisory) Patсh Feed
DLA (Debian Security Advisory) Vulnerability Feed
ALT Linux (Security Bulletins) Patсh Statistics
ALT Linux (Security Bulletins) Patсh Feed
ALT Linux (Security Bulletins) Vulnerability Feed
RED OS (Security Bulletins) Patсh Statistics
RED OS (Security Bulletins) Patсh Feed
RED OS (Security Bulletins) Vulnerability Feed
USN (Ubuntu Security Notice) Patсh Statistics
USN (Ubuntu Security Notice) Patсh Feed
USN (Ubuntu Security Notice) Vulnerability Feed
RHSA (RedHat Security Advisory) Patсh Statistics
RHSA (RedHat Security Advisory) Patсh Feed
RHSA (RedHat Security Advisory) Vulnerability Feed
ELSA (Oracle Linux Security Advisory) Patсh Statistics
ELSA (Oracle Linux Security Advisory) Patсh Feed
ELSA (Oracle Linux Security Advisory) Vulnerability Feed
SUSE (SUSE Security Advisories) Patсh Statistics
SUSE (SUSE Security Advisories) Patсh Feed
SUSE (SUSE Security Advisories) Vulnerability Feed
openSUSE (openSUSE Security Advisories) Patсh Statistics
openSUSE (openSUSE Security Advisories) Patсh Feed
openSUSE (openSUSE Security Advisories) Vulnerability Feed
Amazon Linux AMI (Security Bulletins) Patсh Statistics
Amazon Linux AMI (Security Bulletins) Patсh Feed
Amazon Linux AMI (Security Bulletins) Vulnerability Feed
Mageia Linux (Security Bulletins) Patсh Statistics
Mageia Linux (Security Bulletins) Patсh Feed
Mageia Linux (Security Bulletins) Vulnerability Feed
OS ROSA SX COBALT 1.0
OS ROSA DX COBALT 1.0
ROSA 7.3 (Security Advisories) Patсh Statistics
ROSA 7.3 (Security Advisories) Patсh Feed
ROSA 7.3 (Security Advisories) Vulnerability Feed
ALT Linux SPT 6.0
ALT Linux SPT 7.0
ALT 8 SP
ALT 9
Astra Linux SE 1.5
Astra Linux SE 1.6
Astra Linux SE 1.7
Astra Linux SE 1.8
RED OS Murom 7.1
RED OS Murom 7.2
IBM DB2
VMware Vulnerabilities Advisory (VMSA)
VMware vCenter Patch Advisories
VMware ESXi Patch Advisories
VMware NSX Patches
VMware NSX Vulnerabilities
VMware Photon OS 1.0 Patches
VMware Photon OS 1.0 Vulnerabilities
VMware Photon OS 2.0 Patches
VMware Photon OS 2.0 Vulnerabilities
Cisco ASA
Cisco IOS/NX-OS Advisory
Cisco NX-OS Vulnerabilities
Check Point Gaia
Apache Tomcat Advisories
Apache Tomcat Server
Apache HTTP Server
Python
Node.js
RubyGems
Qt
Microsoft Security Bulletin
Microsoft Knowledge Base Article
Microsoft SharePoint
Microsoft SharePoint Foundation 2013
Microsoft SharePoint Server 2013
Microsoft SharePoint Server 2016
About OVALdb
User manual
Pricing
Contact us
OVAL Definitions
>
OVAL Definition Details
Id
oval:com.altx-soft.nix:def:14138
[Rus]
Version
9
Class
patch
ALTXid
27538
Language
English
Severity
Critical
Title
USN-1141-1 -- linux, linux-ec2 vulnerabilities
Description
linux: Linux kernel - linux-ec2: Linux kernel for EC2 Multiple kernel vulnerabilities have been fixed.
Family
unix
Platform
Ubuntu 10.04
Product
linux
linux-ec2
Reference
CVE: CVE-2011-1083
CVE: CVE-2011-1083
Id:
CVE-2011-1083
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1083
Comment
: The epoll implementation in the Linux kernel 2.6.37.2 and earlier does not properly traverse a tree of epoll file descriptors, which allows local users to cause a denial of service (CPU consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
400 (Uncontrolled Resource Consumption ('Resource Exhaustion'))
References:
[linux-kernel] 20110225 [PATCH] optimize epoll loop detection (MLIST)
[oss-security] 20110302 Re: CVE request: kernel: Multiple DoS issues in epoll (MLIST)
[linux-kernel] 20110228 Re: [PATCH] optimize epoll loop detection (MLIST)
[oss-security] 20110301 CVE request: kernel: Multiple DoS issues in epoll (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=681578 (CONFIRM)
43522 (SECUNIA)
71265 (OSVDB)
[linux-kernel] 20110226 Re: [PATCH] optimize epoll loop detection (MLIST)
RHSA-2012:0862 (REDHAT)
48898 (SECUNIA)
48964 (SECUNIA)
SUSE-SU-2012:0616 (SUSE)
SUSE-SU-2012:0554 (SUSE)
48410 (SECUNIA)
48115 (SECUNIA)
VENDOR: USN-1141-1
VENDOR: USN-1141-1
Id:
USN-1141-1
Reference:
https://usn.ubuntu.com/usn/usn-1141-1
CVE: CVE-2011-4913
CVE: CVE-2011-4913
Id:
CVE-2011-4913
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4913
Comment
: The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP fields, which allows remote attackers to (1) cause a denial of service (integer underflow, heap memory corruption, and panic) via a small length value in data sent to a ROSE socket, or (2) conduct stack-based buffer overflow attacks via a large length value in data sent to a ROSE socket.
CVSSv2 Score:
7.8
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE:
20 (Improper Input Validation)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=770777 (CONFIRM)
https://github.com/torvalds/linux/commit/be20250c13f88375345ad99950190685eda51eb8 (CONFIRM)
[oss-security] 20111227 Re: CVE request: kernel: multiple issues in ROSE (MLIST)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
SUSE-SU-2015:0812 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=be20250c13f88375345ad99950190685eda51eb8 (MISC)
CVE: CVE-2011-4611
CVE: CVE-2011-4611
Id:
CVE-2011-4611
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4611
Comment
: Integer overflow in the perf_event_interrupt function in arch/powerpc/kernel/perf_event.c in the Linux kernel before 2.6.39 on powerpc platforms allows local users to cause a denial of service (unhandled performance monitor exception) via vectors that trigger certain outcomes of performance events.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
189 (Numeric Errors)
References:
https://github.com/torvalds/linux/commit/0837e3242c73566fc1c0196b4ec61779c25ffc93 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=767914 (CONFIRM)
[oss-security] 20111215 Re: CVE request - kernel: perf, powerpc: Handle events that raise an exception without overflowing (MLIST)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0837e3242c73566fc1c0196b4ec61779c25ffc93 (MISC)
CVE: CVE-2011-3359
CVE: CVE-2011-3359
Id:
CVE-2011-3359
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3359
Comment
: The dma_rx function in drivers/net/wireless/b43/dma.c in the Linux kernel before 2.6.39 does not properly allocate receive buffers, which allows remote attackers to cause a denial of service (system crash) via a crafted frame.
CVSSv2 Score:
7.8
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
7.5
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
References:
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
https://github.com/torvalds/linux/commit/c85ce65ecac078ab1a1835c87c4a6319cf74660a (CONFIRM)
[oss-security] 20110914 Re: CVE request -- kernel: b43: allocate receive buffers big enough for max frame len + offset (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=738202 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c85ce65ecac078ab1a1835c87c4a6319cf74660a (MISC)
CVE: CVE-2011-1573
CVE: CVE-2011-1573
Id:
CVE-2011-1573
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1573
Comment
: net/sctp/sm_make_chunk.c in the Linux kernel before 2.6.34, when addip_enable and auth_enable are used, does not consider the amount of zero padding during calculation of chunk lengths for (1) INIT and (2) INIT ACK chunks, which allows remote attackers to cause a denial of service (OOPS) via crafted packet data.
CVSSv2 Score:
4.3
Access vector:
NETWORK
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P
CVSSv3 Score:
5.9
Attack vector:
NETWORK
Attack complexity:
HIGH
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
682 (Incorrect Calculation)
References:
[oss-security] 20110411 CVE request - kernel: sctp: fix to calc the INIT/INIT-ACK chunk length correctly to set (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=695383 (CONFIRM)
http://mirror.anl.gov/pub/linux/kernel/v2.6/ChangeLog-2.6.34 (CONFIRM)
[oss-security] 20110411 Re: CVE request - kernel: sctp: fix to calc the INIT/INIT-ACK chunk length correctly to set (MLIST)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a8170c35e738d62e9919ce5b109cf4ed66e95bde (MISC)
CVE: CVE-2011-1478
CVE: CVE-2011-1478
Id:
CVE-2011-1478
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1478
Comment
: The napi_reuse_skb function in net/core/dev.c in the Generic Receive Offload (GRO) implementation in the Linux kernel before 2.6.38 does not reset the values of certain structure members, which might allow remote attackers to cause a denial of service (NULL pointer dereference) via a malformed VLAN frame.
CVSSv2 Score:
5.7
Access vector:
ADJACENT_NETWORK
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:A/AC:M/Au:N/C:N/I:N/A:C
CWE:
476 (NULL Pointer Dereference)
References:
http://mirror.anl.gov/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=691270 (CONFIRM)
46397 (SECUNIA)
[oss-security] 20110328 CVE-2011-1478 kernel: gro: reset dev and skb_iff on skb reuse (MLIST)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
8480 (SREASON)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6d152e23ad1a7a5b40fef1f42e017d66e6115159 (MISC)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=66c46d741e2e60f0e8b625b80edb0ab820c46d7a (MISC)
CVE: CVE-2011-1477
CVE: CVE-2011-1477
Id:
CVE-2011-1477
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1477
Comment
: Multiple array index errors in sound/oss/opl3.c in the Linux kernel before 2.6.39 allow local users to cause a denial of service (heap memory corruption) or possibly gain privileges by leveraging write access to /dev/sequencer.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
264 (Permissions, Privileges, and Access Controls)
References:
https://github.com/torvalds/linux/commit/4d00135a680727f6c3be78f8befaac009030e4df (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110325 Re: CVE request: kernel: two OSS fixes (MLIST)
SUSE-SU-2015:0812 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4d00135a680727f6c3be78f8befaac009030e4df (MISC)
CVE: CVE-2011-1476
CVE: CVE-2011-1476
Id:
CVE-2011-1476
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1476
Comment
: Integer underflow in the Open Sound System (OSS) subsystem in the Linux kernel before 2.6.39 on unspecified non-x86 platforms allows local users to cause a denial of service (memory corruption) by leveraging write access to /dev/sequencer.
CVSSv2 Score:
4
Access vector:
LOCAL
Access complexity:
HIGH
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:H/Au:N/C:N/I:N/A:C
CWE:
189 (Numeric Errors)
References:
https://github.com/torvalds/linux/commit/b769f49463711205d57286e64cf535ed4daf59e9 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110325 Re: CVE request: kernel: two OSS fixes (MLIST)
SUSE-SU-2015:0812 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b769f49463711205d57286e64cf535ed4daf59e9 (MISC)
CVE: CVE-2011-1182
CVE: CVE-2011-1182
Id:
CVE-2011-1182
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1182
Comment
: kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a signal sender via a sigqueueinfo system call.
CVSSv2 Score:
3.6
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:P/A:P
References:
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=690028 (CONFIRM)
https://github.com/torvalds/linux/commit/da48524eb20662618854bb3df2db01fc65f3070c (CONFIRM)
[oss-security] 20110323 Re: Linux kernel signal spoofing vulnerability (CVE request) (MLIST)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=da48524eb20662618854bb3df2db01fc65f3070c (MISC)
CVE: CVE-2011-1180
CVE: CVE-2011-1180
Id:
CVE-2011-1180
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1180
Comment
: Multiple stack-based buffer overflows in the iriap_getvaluebyclass_indication function in net/irda/iriap.c in the Linux kernel before 2.6.39 allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging connectivity to an IrDA infrared network and sending a large integer value for a (1) name length or (2) attribute length.
CVSSv2 Score:
7.5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSSv3 Score:
9.8
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE:
787 (Out-of-bounds Write)
References:
https://github.com/torvalds/linux/commit/d370af0ef7951188daeb15bae75db7ba57c67846 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110322 Re: CVE requests - kernel: irda/decnet issues (MLIST)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d370af0ef7951188daeb15bae75db7ba57c67846 ()
CVE: CVE-2011-1173
CVE: CVE-2011-1173
Id:
CVE-2011-1173
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1173
Comment
: The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.39 on the x86_64 platform allows remote attackers to obtain potentially sensitive information from kernel stack memory by reading uninitialized data in the ah field of an Acorn Universal Networking (AUN) packet.
CVSSv2 Score:
5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[netdev] 20110317 [PATCH] econet: 4 byte infoleak to the network (MLIST)
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=591815#c14 (MISC)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
8279 (SREASON)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=67c5c6cb8129c595f21e88254a3fc6b3b841ae8e (MISC)
CVE: CVE-2011-2534
CVE: CVE-2011-2534
Id:
CVE-2011-2534
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2534
Comment
: Buffer overflow in the clusterip_proc_write function in net/ipv4/netfilter/ipt_CLUSTERIP.c in the Linux kernel before 2.6.39 might allow local users to cause a denial of service or have unspecified other impact via a crafted write operation, related to string data that lacks a terminating '\0' character.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'))
References:
[netfilter] 20110310 [PATCH] ipv4: netfilter: ipt_CLUSTERIP: fix buffer overflow (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=689337 (CONFIRM)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[netfilter-devel] 20110317 [PATCH v2] ipv4: netfilter: ipt_CLUSTERIP: fix buffer overflow (MLIST)
46921 (BID)
8284 (SREASON)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=961ed183a9fd080cf306c659b8736007e44065a5 ()
CVE: CVE-2011-1172
CVE: CVE-2011-1172
Id:
CVE-2011-1172
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1172
Comment
: net/ipv6/netfilter/ip6_tables.c in the IPv6 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
[linux-kernel] 20110310 [PATCH] ipv6: netfilter: ip6_tables: fix infoleak to userspace (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=689345 (CONFIRM)
8278 (SREASON)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6a8ab060779779de8aea92ce3337ca348f973f54 (MISC)
CVE: CVE-2011-1171
CVE: CVE-2011-1171
Id:
CVE-2011-1171
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1171
Comment
: net/ipv4/netfilter/ip_tables.c in the IPv4 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
[linux-kernel] 20110310 [PATCH] ipv4: netfilter: ip_tables: fix infoleak to userspace (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=689327 (CONFIRM)
8278 (SREASON)
8283 (SREASON)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=78b79876761b86653df89c48a7010b5cbd41a84a (MISC)
CVE: CVE-2011-1170
CVE: CVE-2011-1170
Id:
CVE-2011-1170
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1170
Comment
: net/ipv4/netfilter/arp_tables.c in the IPv4 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[netfilter-devel] 20110310 [PATCH] ipv4: netfilter: arp_tables: fix infoleak to userspace (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=689321 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
8282 (SREASON)
8278 (SREASON)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=42eab94fff18cb1091d3501cd284d6bd6cc9c143 (MISC)
CVE: CVE-2011-1160
CVE: CVE-2011-1160
Id:
CVE-2011-1160
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1160
Comment
: The tpm_open function in drivers/char/tpm/tpm.c in the Linux kernel before 2.6.39 does not initialize a certain buffer, which allows local users to obtain potentially sensitive information from kernel memory via unspecified vectors.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://github.com/torvalds/linux/commit/1309d7afbed112f0e8e90be9af975550caa0076b (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=684671 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110315 Re: CVE requests - kernel: tpm infoleaks (MLIST)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1309d7afbed112f0e8e90be9af975550caa0076b (MISC)
CVE: CVE-2011-1093
CVE: CVE-2011-1093
Id:
CVE-2011-1093
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1093
Comment
: The dccp_rcv_state_process function in net/dccp/input.c in the Datagram Congestion Control Protocol (DCCP) implementation in the Linux kernel before 2.6.38 does not properly handle packets for a CLOSED endpoint, which allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending a DCCP-Close packet followed by a DCCP-Reset packet.
CVSSv2 Score:
7.8
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE:
476 (NULL Pointer Dereference)
References:
46793 (BID)
https://bugzilla.redhat.com/show_bug.cgi?id=682954 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
[oss-security] 20110308 CVE request: kernel: dccp: fix oops on Reset after close (MLIST)
[oss-security] 20110308 Re: CVE request: kernel: dccp: fix oops on Reset after close (MLIST)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=720dc34bbbe9493c7bd48b2243058b4e447a929d (MISC)
CVE: CVE-2011-1082
CVE: CVE-2011-1082
Id:
CVE-2011-1082
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1082
Comment
: fs/eventpoll.c in the Linux kernel before 2.6.38 places epoll file descriptors within other epoll data structures without properly checking for (1) closed loops or (2) deep chains, which allows local users to cause a denial of service (deadlock or stack memory consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
400 (Uncontrolled Resource Consumption ('Resource Exhaustion'))
References:
[oss-security] 20110301 CVE request: kernel: Multiple DoS issues in epoll (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=681575 (CONFIRM)
[oss-security] 20110302 Re: CVE request: kernel: Multiple DoS issues in epoll (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
[linux-kernel] 20110205 [PATCH] epoll: Prevent deadlock through unsafe ->f_op->poll() calls. (MLIST)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e (MISC)
CVE: CVE-2011-1080
CVE: CVE-2011-1080
Id:
CVE-2011-1080
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1080
Comment
: The do_replace function in net/bridge/netfilter/ebtables.c in the Linux kernel before 2.6.39 does not ensure that a certain name field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory by leveraging the CAP_NET_ADMIN capability to replace a table, and then reading a modprobe command line.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
20 (Improper Input Validation)
References:
[oss-security] 20110301 Re: CVE request: kernel: two bluetooth and one ebtables infoleaks/DoSes (MLIST)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=681262 (CONFIRM)
https://github.com/torvalds/linux/commit/d846f71195d57b0bbb143382647c2c6638b04c5a (CONFIRM)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d846f71195d57b0bbb143382647c2c6638b04c5a (MISC)
CVE: CVE-2011-1079
CVE: CVE-2011-1079
Id:
CVE-2011-1079
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1079
Comment
: The bnep_sock_ioctl function in net/bluetooth/bnep/sock.c in the Linux kernel before 2.6.39 does not ensure that a certain device field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory, or cause a denial of service (BUG and system crash), via a BNEPCONNADD command.
CVSSv2 Score:
5.4
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:C
CWE:
20 (Improper Input Validation)
References:
https://github.com/torvalds/linux/commit/43629f8f5ea32a998d06d1bb41eefa0e821ff573 (CONFIRM)
[oss-security] 20110301 Re: CVE request: kernel: two bluetooth and one ebtables infoleaks/DoSes (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=681260 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://packetstormsecurity.com/files/153799/Kernel-Live-Patch-Security-Notice-LSN-0053-1.html (MISC)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=43629f8f5ea32a998d06d1bb41eefa0e821ff573 (MISC)
CVE: CVE-2011-1078
CVE: CVE-2011-1078
Id:
CVE-2011-1078
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1078
Comment
: The sco_sock_getsockopt_old function in net/bluetooth/sco.c in the Linux kernel before 2.6.39 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via the SCO_CONNINFO option.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110301 Re: CVE request: kernel: two bluetooth and one ebtables infoleaks/DoSes (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=681259 (CONFIRM)
https://github.com/torvalds/linux/commit/c4c896e1471aec3b004a693c689f60be3b17ac86 (CONFIRM)
RHSA-2012:1156 (REDHAT)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c4c896e1471aec3b004a693c689f60be3b17ac86 (MISC)
CVE: CVE-2011-1019
CVE: CVE-2011-1019
Id:
CVE-2011-1019
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1019
Comment
: The dev_load function in net/core/dev.c in the Linux kernel before 2.6.38 allows local users to bypass an intended CAP_SYS_MODULE capability requirement and load arbitrary modules by leveraging the CAP_NET_ADMIN capability.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
PARTIAL
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:P/A:N
References:
https://github.com/torvalds/linux/commit/8909c9ad8ff03611c9c96c9a92656213e4bb495b (CONFIRM)
[oss-security] 20110225 Re: CVE request: kernel: CAP_SYS_MODULE bypass via CAP_NET_ADMIN (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=680360 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8909c9ad8ff03611c9c96c9a92656213e4bb495b (MISC)
CVE: CVE-2011-1016
CVE: CVE-2011-1016
Id:
CVE-2011-1016
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1016
Comment
: The Radeon GPU drivers in the Linux kernel before 2.6.38-rc5 do not properly validate data related to the AA resolve registers, which allows local users to write to arbitrary memory locations associated with (1) Video RAM (aka VRAM) or (2) the Graphics Translation Table (GTT) via crafted values.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
PARTIAL
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:P/A:N
CWE:
20 (Improper Input Validation)
References:
[oss-security] 20110224 CVE request: kernel: drm/radeon/kms: check AA resolve registers on r300 (MLIST)
46557 (BID)
[oss-security] 20110224 Re: CVE request: kernel: drm/radeon/kms: check AA resolve registers on r300 (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.38-rc5 (CONFIRM)
[oss-security] 20110225 Re: CVE request: kernel: drm/radeon/kms: check AA resolve registers on r300 (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=680000 (CONFIRM)
kernel-atiradeon-sec-bypass(65691) (XF)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fff1ce4dc6113b6fdc4e3a815ca5fd229408f8ef (MISC)
CVE: CVE-2011-1013
CVE: CVE-2011-1013
Id:
CVE-2011-1013
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1013
Comment
: Integer signedness error in the drm_modeset_ctl function in (1) drivers/gpu/drm/drm_irq.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.38 and (2) sys/dev/pci/drm/drm_irq.c in the kernel in OpenBSD before 4.9 allows local users to trigger out-of-bounds write operations, and consequently cause a denial of service (system crash) or possibly have unspecified other impact, via a crafted num_crtcs (aka vb_num) structure member in an ioctl argument.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
787 (Out-of-bounds Write)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38 (CONFIRM)
http://www.openbsd.org/cgi-bin/cvsweb/src/sys/dev/pci/drm/drm_irq.c (CONFIRM)
47639 (BID)
https://bugzilla.redhat.com/show_bug.cgi?id=679925 (CONFIRM)
kernel-drmioctl-priv-escalation(67199) (XF)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1922756124ddd53846877416d92ba4a802bc658f (MISC)
http://www.openbsd.org/cgi-bin/cvsweb/src/sys/dev/pci/drm/drm_irq.c.diff?r1=1.41%3Br2=1.42%3Bf=h (MISC)
CVE: CVE-2011-1012
CVE: CVE-2011-1012
Id:
CVE-2011-1012
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1012
Comment
: The ldm_parse_vmdb function in fs/partitions/ldm.c in the Linux kernel before 2.6.38-rc6-git6 does not validate the VBLK size value in the VMDB structure in an LDM partition table, which allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted partition table.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
369 (Divide By Zero)
References:
[mm-commits] 20110222 + ldm-corrupted-partition-table-can-cause-kernel-oops.patch added to -mm tree (MLIST)
[oss-security] 20110223 CVE request: kernel: Corrupted LDM partition table issues (MLIST)
[oss-security] 20110223 Re: CVE request: kernel: Corrupted LDM partition table issues (MLIST)
http://www.pre-cert.de/advisories/PRE-SA-2011-01.txt (MISC)
http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.38-rc6-git6.log (CONFIRM)
1025127 (SECTRACK)
46512 (BID)
8115 (SREASON)
USN-1146-1 (UBUNTU)
20110223 [PRE-SA-2011-01] Multiple Linux kernel vulnerabilities in partition handling code of LDM and MAC partition tables (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=294f6cf48666825d23c9372ef37631232746e40d (MISC)
CVE: CVE-2011-1010
CVE: CVE-2011-1010
Id:
CVE-2011-1010
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1010
Comment
: Buffer overflow in the mac_partition function in fs/partitions/mac.c in the Linux kernel before 2.6.37.2 allows local users to cause a denial of service (panic) or possibly have unspecified other impact via a malformed Mac OS partition table.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'))
References:
https://bugzilla.redhat.com/show_bug.cgi?id=679282 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37.2 (CONFIRM)
[oss-security] 20110222 Re: CVE request: kernel: fs/partitions: validate map_count in mac partition tables (MLIST)
http://www.pre-cert.de/advisories/PRE-SA-2011-01.txt (MISC)
[oss-security] 20110222 CVE request: kernel: fs/partitions: validate map_count in mac partition tables (MLIST)
[oss-security] 20110222 Re: CVE request: kernel: fs/partitions: validate map_count in mac partition tables (MLIST)
1025126 (SECTRACK)
46492 (BID)
8115 (SREASON)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
kernel-map-dos(65643) (XF)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
20110223 [PRE-SA-2011-01] Multiple Linux kernel vulnerabilities in partition handling code of LDM and MAC partition tables (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fa7ea87a057958a8b7926c1a60a3ca6d696328ed (MISC)
CVE: CVE-2011-0726
CVE: CVE-2011-0726
Id:
CVE-2011-0726
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0726
Comment
: The do_task_stat function in fs/proc/array.c in the Linux kernel before 2.6.39-rc1 does not perform an expected uid check, which makes it easier for local users to defeat the ASLR protection mechanism by reading the start_code and end_code fields in the /proc/#####/stat file for a process executing a PIE binary.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
20 (Improper Input Validation)
References:
[linux-kernel] 20110311 [PATCH] proc: protect mm start_code/end_code in /proc/pid/stat (MLIST)
[mm-commits] 20110314 + proc-protect-mm-start_code-end_code-in-proc-pid-stat.patch added to -mm tree (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=684569 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/v2.6.39/ChangeLog-2.6.39-rc1 (CONFIRM)
47791 (BID)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=5883f57ca0008ffc93e09cbb9847a1928e50c6f3 ()
CVE: CVE-2011-0712
CVE: CVE-2011-0712
Id:
CVE-2011-0712
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0712
Comment
: Multiple buffer overflows in the caiaq Native Instruments USB audio functionality in the Linux kernel before 2.6.38-rc4-next-20110215 might allow attackers to cause a denial of service or possibly have unspecified other impact via a long USB device name, related to (1) the snd_usb_caiaq_audio_init function in sound/usb/caiaq/audio.c and (2) the snd_usb_caiaq_midi_init function in sound/usb/caiaq/midi.c.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'))
References:
[oss-security] 20110216 kernel: ALSA: caiaq - Fix possible string-buffer overflow (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/next/patch-v2.6.38-rc4-next-20110215.bz2 (CONFIRM)
46419 (BID)
[oss-security] 20110216 Re: kernel: ALSA: caiaq - Fix possible string-buffer overflow (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=677881 (CONFIRM)
[oss-security] 20110216 Re: kernel: ALSA: caiaq - Fix possible string-buffer overflow (MLIST)
USN-1146-1 (UBUNTU)
kernel-usbdevice-bo(65461) (XF)
http://git.kernel.org/?p=linux/kernel/git/tiwai/sound-2.6.git%3Ba=commit%3Bh=eaae55dac6b64c0616046436b294e69fc5311581 (MISC)
CVE: CVE-2011-0711
CVE: CVE-2011-0711
Id:
CVE-2011-0711
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0711
Comment
: The xfs_fs_geometry function in fs/xfs/xfs_fsops.c in the Linux kernel before 2.6.38-rc6-git3 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FSGEOMETRY_V1 ioctl call.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=677260 (CONFIRM)
46417 (BID)
[oss-security] 20110216 Re: CVE request - kernel: xfs infoleak (MLIST)
[oss-security] 20110216 CVE request - kernel: xfs infoleak (MLIST)
https://patchwork.kernel.org/patch/555461/ (CONFIRM)
70950 (OSVDB)
http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.38-rc6-git3.log (CONFIRM)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3a3675b7f23f83ca8c67c9c2b6edf707fd28d1ba (MISC)
CVE: CVE-2011-0695
CVE: CVE-2011-0695
Id:
CVE-2011-0695
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0695
Comment
: Race condition in the cm_work_handler function in the InfiniBand driver (drivers/infiniband/core/cma.c) in Linux kernel 2.6.x allows remote attackers to cause a denial of service (panic) by sending an InfiniBand request while other request handlers are still running, which triggers an invalid pointer dereference.
CVSSv2 Score:
5.7
Access vector:
ADJACENT_NETWORK
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:A/AC:M/Au:N/C:N/I:N/A:C
CWE:
362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'))
References:
[linux-rdma] 20110223 [PATCH 2/2] ib/cm: Bump reference count on cm_id before invoking callback (MLIST)
43693 (SECUNIA)
46839 (BID)
[linux-rdma] 20110223 [PATCH 1/2] rdma/cm: Fix crash in request handlers (MLIST)
[oss-security] 20110311 CVE-2011-0695 kernel: panic in ib_cm:cm_work_handler (MLIST)
USN-1146-1 (UBUNTU)
RHSA-2011:0927 (REDHAT)
kernel-infiniband-dos(66056) (XF)
CVE: CVE-2011-0521
CVE: CVE-2011-0521
Id:
CVE-2011-0521
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0521
Comment
: The dvb_ca_ioctl function in drivers/media/dvb/ttpci/av7110_ca.c in the Linux kernel before 2.6.38-rc2 does not check the sign of a certain integer field, which allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a negative value.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.38-rc2 (CONFIRM)
[oss-security] 20110125 Re: Linux kernel av7110 negative array offset (MLIST)
43009 (SECUNIA)
[oss-security] 20110125 Linux kernel av7110 negative array offset (MLIST)
45986 (BID)
1025195 (SECTRACK)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
kernel-av7110ca-privilege-escalation(64988) (XF)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=cb26a24ee9706473f31d34cc259f4dcf45cd0644 (MISC)
CVE: CVE-2011-0463
CVE: CVE-2011-0463
Id:
CVE-2011-0463
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0463
Comment
: The ocfs2_prepare_page_for_write function in fs/ocfs2/aops.c in the Oracle Cluster File System 2 (OCFS2) subsystem in the Linux kernel before 2.6.39-rc1 does not properly handle holes that cross page boundaries, which allows local users to obtain potentially sensitive information from uninitialized disk locations by reading a file.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
20 (Improper Input Validation)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.39-rc1 (CONFIRM)
[ocfs2-devel] 20110217 [PATCH] Treat writes as new when holes span across page boundaries (MLIST)
43966 (SECUNIA)
https://bugzilla.novell.com/show_bug.cgi?id=673037 (CONFIRM)
USN-1146-1 (UBUNTU)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=272b62c1f0f6f742046e45b50b6fec98860208a0 ()
CVE: CVE-2010-4656
CVE: CVE-2010-4656
Id:
CVE-2010-4656
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4656
Comment
: The iowarrior_write function in drivers/usb/misc/iowarrior.c in the Linux kernel before 2.6.37 does not properly allocate memory, which might allow local users to trigger a heap-based buffer overflow, and consequently cause a denial of service or gain privileges, via a long report.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
787 (Out-of-bounds Write)
References:
[oss-security] 20110125 Re: CVE request: linux kernel heap issues (MLIST)
[oss-security] 20110124 Re: CVE request: linux kernel heap issues (MLIST)
46069 (BID)
https://bugzilla.redhat.com/show_bug.cgi?id=672420 (CONFIRM)
[oss-security] 20110124 CVE request: linux kernel heap issues (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37 (CONFIRM)
USN-1146-1 (UBUNTU)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3ed780117dbe5acb64280d218f0347f238dafed0 (MISC)
CVE: CVE-2010-4565
CVE: CVE-2010-4565
Id:
CVE-2010-4565
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4565
Comment
: The bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel 2.6.36 and earlier creates a publicly accessible file with a filename containing a kernel memory address, which allows local users to obtain potentially sensitive information about kernel memory use by listing this filename.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20101220 CVE request: kernel: CAN information leak, 2nd attempt (MLIST)
[netdev] 20101110 Re: [PATCH] Fix CAN info leak/minor heap overflow (MLIST)
[netdev] 20101109 Re: [PATCH] Fix CAN info leak/minor heap overflow (MLIST)
[netdev] 20101102 [SECURITY] CAN info leak/minor heap overflow (MLIST)
[oss-security] 20101104 Re: CVE request: kernel: CAN information leak (MLIST)
[oss-security] 20101103 CVE request: kernel: CAN information leak (MLIST)
44661 (BID)
[oss-security] 20101220 Re: CVE request: kernel: CAN information leak, 2nd attempt (MLIST)
[netdev] 20101102 Re: [SECURITY] CAN info leak/minor heap overflow (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=664544 (MISC)
MDVSA-2011:029 (MANDRIVA)
CVE: CVE-2010-4529
CVE: CVE-2010-4529
Id:
CVE-2010-4529
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4529
Comment
: Integer underflow in the irda_getsockopt function in net/irda/af_irda.c in the Linux kernel before 2.6.37 on platforms other than x86 allows local users to obtain potentially sensitive information from kernel heap memory via an IRLMP_ENUMDEVICES getsockopt call.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
191 (Integer Underflow (Wrap or Wraparound))
References:
[oss-security] 20110103 Re: CVE request: kernel: irda: prevent integer underflow in IRLMP_ENUMDEVICES (MLIST)
42684 (SECUNIA)
[oss-security] 20101223 CVE request: kernel: irda: prevent integer underflow in IRLMP_ENUMDEVICES (MLIST)
[netdev] 20101222 [PATCH] irda: prevent integer underflow in IRLMP_ENUMDEVICES (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37 (CONFIRM)
45556 (BID)
SUSE-SA:2011:008 (SUSE)
43291 (SECUNIA)
ADV-2011-0375 (VUPEN)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fdac1e0697356ac212259f2147aa60c72e334861 ()
CVE: CVE-2010-4342
CVE: CVE-2010-4342
Id:
CVE-2010-4342
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4342
Comment
: The aun_incoming function in net/econet/af_econet.c in the Linux kernel before 2.6.37-rc6, when Econet is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending an Acorn Universal Networking (AUN) packet over UDP.
CVSSv2 Score:
7.1
Access vector:
NETWORK
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:C
CWE:
476 (NULL Pointer Dereference)
References:
[oss-security] 20101208 CVE request: kernel: NULL pointer dereference in AF_ECONET (MLIST)
[oss-security] 20101209 Re: CVE request: kernel: NULL pointer dereference in AF_ECONET (MLIST)
[netdev] 20101209 NULL dereference in econet AUN-over-UDP receive (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc6 (CONFIRM)
[netdev] 20101209 Re: NULL dereference in econet AUN-over-UDP receive (MLIST)
45321 (BID)
ADV-2011-0375 (VUPEN)
43291 (SECUNIA)
SUSE-SA:2011:008 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4e085e76cbe558b79b54cbab772f61185879bc64 (MISC)
CVE: CVE-2010-4263
CVE: CVE-2010-4263
Id:
CVE-2010-4263
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4263
Comment
: The igb_receive_skb function in drivers/net/igb/igb_main.c in the Intel Gigabit Ethernet (aka igb) subsystem in the Linux kernel before 2.6.34, when Single Root I/O Virtualization (SR-IOV) and promiscuous mode are enabled but no VLANs are registered, allows remote attackers to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact via a VLAN tagged frame.
CVSSv2 Score:
7.9
Access vector:
ADJACENT_NETWORK
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:A/AC:M/Au:N/C:C/I:C/A:C
CWE:
476 (NULL Pointer Dereference)
References:
https://bugzilla.kernel.org/show_bug.cgi?id=15582 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.34 (CONFIRM)
[oss-security] 20101206 Re: CVE request: kernel: igb panics when receiving tag vlan packet (MLIST)
45208 (BID)
[oss-security] 20101206 CVE request: kernel: igb panics when receiving tag vlan packet (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=660188 (CONFIRM)
42890 (SECUNIA)
RHSA-2011:0017 (REDHAT)
RHSA-2011:0007 (REDHAT)
42884 (SECUNIA)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=31b24b955c3ebbb6f3008a6374e61cf7c05a193c (MISC)
CVE: CVE-2010-4243
CVE: CVE-2010-4243
Id:
CVE-2010-4243
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4243
Comment
: fs/exec.c in the Linux kernel before 2.6.37 does not enable the OOM Killer to assess use of stack memory by arrays representing the (1) arguments and (2) environment, which allows local users to cause a denial of service (memory consumption) via a crafted exec system call, aka an "OOM dodging issue," a related issue to CVE-2010-3858.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
400 (Uncontrolled Resource Consumption ('Resource Exhaustion'))
References:
[oss-security] 20101122 CVE request: kernel: mm: mem allocated invisible to oom_kill() when not attached to any threads (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=625688 (CONFIRM)
[linux-kernel] 20100830 Re: [PATCH] exec argument expansion can inappropriately trigger OOM-killer (MLIST)
[linux-kernel] 20100830 Re: [PATCH] exec argument expansion can inappropriately trigger OOM-killer (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37 (CONFIRM)
15619 (EXPLOIT-DB)
[linux-kernel] 20100827 [PATCH] exec argument expansion can inappropriately trigger OOM-killer (MLIST)
[oss-security] 20101122 Re: CVE request: kernel: mm: mem allocated invisible to oom_kill() when not attached to any threads (MLIST)
[linux-kernel] 20101130 [PATCH 1/2] exec: make argv/envp memory visible to oom-killer (MLIST)
http://grsecurity.net/~spender/64bit_dos.c (MISC)
[linux-kernel] 20100830 Re: [PATCH] exec argument expansion can inappropriately trigger OOM-killer (MLIST)
RHSA-2011:0017 (REDHAT)
42884 (SECUNIA)
45004 (BID)
46397 (SECUNIA)
http://www.vmware.com/security/advisories/VMSA-2011-0012.html (CONFIRM)
linux-kernel-execve-dos(64700) (XF)
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3c77f845722158206a7209c45ccddc264d19319c (MISC)
Content available only for registered users!
ovaldb@altx-soft.com