Professional OVAL Repository
[Eng]
[Rus]
[Sign-In]
OVAL
Search
Categories
RedCheck
About
OVAL Definitions
OVAL Items
FSTEC Data Bank Information Security Threats
NKCKI
EOL (End Of Life)
Linux Security Advisories
Mozilla Foundation Security Advisory
IBM
VMware
Cisco
Check Point Software Technologies
Apache
Solaris
FreeBSD
Development
GitHub Enterprise
Google Chrome Security Advisories
Oracle Security Advisories
Adobe Security Advisories
OpenSSL Security Advisories
Microsoft
CVE
CWE
CPE
Latest Updates
OS ROSA
ALT Linux
Astra Linux SE 1.5
Astra Linux SE 1.6
RED OS
DSA (Debian Security Advisory) Patсh Statistics
DSA (Debian Security Advisory) Patсh Feed
DSA (Debian Security Advisory) Vulnerability Feed
DLA (Debian Security Advisory) Patсh Statistics
DLA (Debian Security Advisory) Patсh Feed
DLA (Debian Security Advisory) Vulnerability Feed
ALT Linux (Security Bulletins) Patсh Statistics
ALT Linux (Security Bulletins) Patсh Feed
ALT Linux (Security Bulletins) Vulnerability Feed
RED OS (Security Bulletins) Patсh Statistics
RED OS (Security Bulletins) Patсh Feed
RED OS (Security Bulletins) Vulnerability Feed
USN (Ubuntu Security Notice) Patсh Statistics
USN (Ubuntu Security Notice) Patсh Feed
USN (Ubuntu Security Notice) Vulnerability Feed
RHSA (RedHat Security Advisory) Patсh Statistics
RHSA (RedHat Security Advisory) Patсh Feed
RHSA (RedHat Security Advisory) Vulnerability Feed
ELSA (Oracle Linux Security Advisory) Patсh Statistics
ELSA (Oracle Linux Security Advisory) Patсh Feed
ELSA (Oracle Linux Security Advisory) Vulnerability Feed
SUSE (SUSE Security Advisories) Patсh Statistics
SUSE (SUSE Security Advisories) Patсh Feed
SUSE (SUSE Security Advisories) Vulnerability Feed
openSUSE (openSUSE Security Advisories) Patсh Statistics
openSUSE (openSUSE Security Advisories) Patсh Feed
openSUSE (openSUSE Security Advisories) Vulnerability Feed
Amazon Linux AMI (Security Bulletins) Patсh Statistics
Amazon Linux AMI (Security Bulletins) Patсh Feed
Amazon Linux AMI (Security Bulletins) Vulnerability Feed
Mageia Linux (Security Bulletins) Patсh Statistics
Mageia Linux (Security Bulletins) Patсh Feed
Mageia Linux (Security Bulletins) Vulnerability Feed
OS ROSA SX COBALT 1.0
OS ROSA DX COBALT 1.0
ROSA 7.3 (Security Advisories) Patсh Statistics
ROSA 7.3 (Security Advisories) Patсh Feed
ROSA 7.3 (Security Advisories) Vulnerability Feed
ALT Linux SPT 6.0
ALT Linux SPT 7.0
ALT 8 SP
ALT 9
RED OS Murom 7.1
RED OS Murom 7.2
IBM DB2
VMware Vulnerabilities Advisory (VMSA)
VMware vCenter Patch Advisories
VMware ESXi Patch Advisories
VMware NSX Patches
VMware NSX Vulnerabilities
VMware Photon OS 1.0 Patches
VMware Photon OS 1.0 Vulnerabilities
VMware Photon OS 2.0 Patches
VMware Photon OS 2.0 Vulnerabilities
Cisco ASA
Cisco IOS/NX-OS Advisory
Cisco NX-OS Vulnerabilities
Check Point Gaia
Apache Tomcat Advisories
Apache Tomcat Server
Apache HTTP Server
Python
Node.js
RubyGems
Qt
Microsoft Security Bulletin
Microsoft Knowledge Base Article
Microsoft SharePoint
Microsoft SharePoint Foundation 2013
Microsoft SharePoint Server 2013
Microsoft SharePoint Server 2016
About OVALdb
User manual
Pricing
Contact us
OVAL Definitions
>
OVAL Definition Details
Id
oval:com.altx-soft.nix:def:25833
[Rus]
Version
5
Class
patch
ALTXid
162530
Language
English
Severity
High
Title
SUSE-SU-2011:0832-1 -- Security update for Linux kernel
Description
The SUSE Linux Enterprise 11 Service Pack 1 kernel was
updated to 2.6.32.43 and fixes various bugs and security issues
Family
unix
Platform
SUSE Linux Enterprise Desktop 11 SP1
SUSE Linux Enterprise Server 11 SP1
Product
kernel-ec2
Reference
VENDOR: SUSE-SU-2011:0832-1
VENDOR: SUSE-SU-2011:0832-1
Id:
SUSE-SU-2011:0832-1
Reference:
http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00012.html
CVE: CVE-2011-1012
CVE: CVE-2011-1012
Id:
CVE-2011-1012
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1012
Comment
: The ldm_parse_vmdb function in fs/partitions/ldm.c in the Linux kernel before 2.6.38-rc6-git6 does not validate the VBLK size value in the VMDB structure in an LDM partition table, which allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted partition table.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
369 (Divide By Zero)
References:
[mm-commits] 20110222 + ldm-corrupted-partition-table-can-cause-kernel-oops.patch added to -mm tree (MLIST)
[oss-security] 20110223 CVE request: kernel: Corrupted LDM partition table issues (MLIST)
[oss-security] 20110223 Re: CVE request: kernel: Corrupted LDM partition table issues (MLIST)
http://www.pre-cert.de/advisories/PRE-SA-2011-01.txt (MISC)
http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.38-rc6-git6.log (CONFIRM)
1025127 (SECTRACK)
46512 (BID)
8115 (SREASON)
USN-1146-1 (UBUNTU)
20110223 [PRE-SA-2011-01] Multiple Linux kernel vulnerabilities in partition handling code of LDM and MAC partition tables (BUGTRAQ)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=294f6cf48666825d23c9372ef37631232746e40d (MISC)
CVE: CVE-2011-1017
CVE: CVE-2011-1017
Id:
CVE-2011-1017
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1017
Comment
: Heap-based buffer overflow in the ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel 2.6.37.2 and earlier might allow local users to gain privileges or obtain sensitive information via a crafted LDM partition table.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
787 (Out-of-bounds Write)
References:
[oss-security] 20110224 Re: CVE request: kernel: fs/partitions: Kernel heap overflow via corrupted LDM partition tables (MLIST)
[oss-security] 20110223 CVE request: kernel: fs/partitions: Kernel heap overflow via corrupted LDM partition tables (MLIST)
http://www.pre-cert.de/advisories/PRE-SA-2011-01.txt (MISC)
1025128 (SECTRACK)
[oss-security] 20110223 Re: CVE request: kernel: fs/partitions: Kernel heap overflow via corrupted LDM partition tables (MLIST)
43738 (SECUNIA)
43716 (SECUNIA)
46512 (BID)
8115 (SREASON)
USN-1146-1 (UBUNTU)
20110223 [PRE-SA-2011-01] Multiple Linux kernel vulnerabilities in partition handling code of LDM and MAC partition tables (BUGTRAQ)
CVE: CVE-2011-1020
CVE: CVE-2011-1020
Id:
CVE-2011-1020
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1020
Comment
: The proc filesystem implementation in the Linux kernel 2.6.37 and earlier does not restrict access to the /proc directory tree of a process after this process performs an exec of a setuid program, which allows local users to obtain sensitive information or cause a denial of service via open, lseek, read, and write system calls.
CVSSv2 Score:
4.6
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE:
200 (Information Exposure)
References:
[oss-security] 20110225 Re: CVE request: kernel: /proc/$pid/ leaks contents across setuid exec (MLIST)
[linux-kernel] 20110209 Re: [SECURITY] /proc/$pid/ leaks contents across setuid exec (MLIST)
43496 (SECUNIA)
[oss-security] 20110224 CVE request: kernel: /proc/$pid/ leaks contents across setuid exec (MLIST)
20110122 Proc filesystem and SUID-Binaries (FULLDISC)
[linux-kernel] 20110208 Re: [SECURITY] /proc/$pid/ leaks contents across setuid exec (MLIST)
[linux-kernel] 20110207 [SECURITY] /proc/$pid/ leaks contents across setuid exec (MLIST)
[linux-kernel] 20110207 Re: [SECURITY] /proc/$pid/ leaks contents across setuid exec (MLIST)
[linux-kernel] 20110209 Re: [SECURITY] /proc/$pid/ leaks contents across setuid exec (MLIST)
http://www.halfdog.net/Security/2011/SuidBinariesAndProcInterface/ (MISC)
[linux-kernel] 20110208 Re: [SECURITY] /proc/$pid/ leaks contents across setuid exec (MLIST)
[linux-kernel] 20110207 Re: [SECURITY] /proc/$pid/ leaks contents across setuid exec (MLIST)
46567 (BID)
8107 (SREASON)
kernel-procpid-security-bypass(65693) (XF)
CVE: CVE-2011-1078
CVE: CVE-2011-1078
Id:
CVE-2011-1078
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1078
Comment
: The sco_sock_getsockopt_old function in net/bluetooth/sco.c in the Linux kernel before 2.6.39 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via the SCO_CONNINFO option.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110301 Re: CVE request: kernel: two bluetooth and one ebtables infoleaks/DoSes (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=681259 (CONFIRM)
https://github.com/torvalds/linux/commit/c4c896e1471aec3b004a693c689f60be3b17ac86 (CONFIRM)
RHSA-2012:1156 (REDHAT)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c4c896e1471aec3b004a693c689f60be3b17ac86 (MISC)
CVE: CVE-2011-1079
CVE: CVE-2011-1079
Id:
CVE-2011-1079
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1079
Comment
: The bnep_sock_ioctl function in net/bluetooth/bnep/sock.c in the Linux kernel before 2.6.39 does not ensure that a certain device field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory, or cause a denial of service (BUG and system crash), via a BNEPCONNADD command.
CVSSv2 Score:
5.4
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:C
CWE:
20 (Improper Input Validation)
References:
https://github.com/torvalds/linux/commit/43629f8f5ea32a998d06d1bb41eefa0e821ff573 (CONFIRM)
[oss-security] 20110301 Re: CVE request: kernel: two bluetooth and one ebtables infoleaks/DoSes (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=681260 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://packetstormsecurity.com/files/153799/Kernel-Live-Patch-Security-Notice-LSN-0053-1.html (MISC)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=43629f8f5ea32a998d06d1bb41eefa0e821ff573 (MISC)
CVE: CVE-2011-1080
CVE: CVE-2011-1080
Id:
CVE-2011-1080
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1080
Comment
: The do_replace function in net/bridge/netfilter/ebtables.c in the Linux kernel before 2.6.39 does not ensure that a certain name field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory by leveraging the CAP_NET_ADMIN capability to replace a table, and then reading a modprobe command line.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
20 (Improper Input Validation)
References:
[oss-security] 20110301 Re: CVE request: kernel: two bluetooth and one ebtables infoleaks/DoSes (MLIST)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=681262 (CONFIRM)
https://github.com/torvalds/linux/commit/d846f71195d57b0bbb143382647c2c6638b04c5a (CONFIRM)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d846f71195d57b0bbb143382647c2c6638b04c5a (MISC)
CVE: CVE-2011-1160
CVE: CVE-2011-1160
Id:
CVE-2011-1160
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1160
Comment
: The tpm_open function in drivers/char/tpm/tpm.c in the Linux kernel before 2.6.39 does not initialize a certain buffer, which allows local users to obtain potentially sensitive information from kernel memory via unspecified vectors.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://github.com/torvalds/linux/commit/1309d7afbed112f0e8e90be9af975550caa0076b (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=684671 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110315 Re: CVE requests - kernel: tpm infoleaks (MLIST)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1309d7afbed112f0e8e90be9af975550caa0076b (MISC)
CVE: CVE-2011-1170
CVE: CVE-2011-1170
Id:
CVE-2011-1170
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1170
Comment
: net/ipv4/netfilter/arp_tables.c in the IPv4 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[netfilter-devel] 20110310 [PATCH] ipv4: netfilter: arp_tables: fix infoleak to userspace (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=689321 (CONFIRM)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
8282 (SREASON)
8278 (SREASON)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=42eab94fff18cb1091d3501cd284d6bd6cc9c143 (MISC)
CVE: CVE-2011-1171
CVE: CVE-2011-1171
Id:
CVE-2011-1171
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1171
Comment
: net/ipv4/netfilter/ip_tables.c in the IPv4 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
[linux-kernel] 20110310 [PATCH] ipv4: netfilter: ip_tables: fix infoleak to userspace (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=689327 (CONFIRM)
8278 (SREASON)
8283 (SREASON)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=78b79876761b86653df89c48a7010b5cbd41a84a (MISC)
CVE: CVE-2011-1172
CVE: CVE-2011-1172
Id:
CVE-2011-1172
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1172
Comment
: net/ipv6/netfilter/ip6_tables.c in the IPv6 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
[linux-kernel] 20110310 [PATCH] ipv6: netfilter: ip6_tables: fix infoleak to userspace (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=689345 (CONFIRM)
8278 (SREASON)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6a8ab060779779de8aea92ce3337ca348f973f54 (MISC)
CVE: CVE-2011-1173
CVE: CVE-2011-1173
Id:
CVE-2011-1173
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1173
Comment
: The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.39 on the x86_64 platform allows remote attackers to obtain potentially sensitive information from kernel stack memory by reading uninitialized data in the ah field of an Acorn Universal Networking (AUN) packet.
CVSSv2 Score:
5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE:
200 (Information Exposure)
References:
[netdev] 20110317 [PATCH] econet: 4 byte infoleak to the network (MLIST)
[oss-security] 20110318 CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
[oss-security] 20110321 Re: CVE request: kernel: netfilter & econet infoleaks (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=591815#c14 (MISC)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
8279 (SREASON)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=67c5c6cb8129c595f21e88254a3fc6b3b841ae8e (MISC)
CVE: CVE-2011-1577
CVE: CVE-2011-1577
Id:
CVE-2011-1577
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1577
Comment
: Heap-based buffer overflow in the is_gpt_valid function in fs/partitions/efi.c in the Linux kernel 2.6.38 and earlier allows physically proximate attackers to cause a denial of service (OOPS) or possibly have unspecified other impact via a crafted size of the EFI GUID partition-table header on removable media.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
References:
47343 (BID)
https://bugzilla.redhat.com/show_bug.cgi?id=695976 (CONFIRM)
[oss-security] 20110413 Re: CVE Request: kernel: fs/partitions: Corrupted GUID partition tables can cause kernel oops (MLIST)
[mm-commits] 20110412 + fs-partitions-efic-corrupted-guid-partition-tables-can-cause-kernel-oops.patch added to -mm tree (MLIST)
[oss-security] 20110412 CVE Request: kernel: fs/partitions: Corrupted GUID partition tables can cause kernel oops (MLIST)
1025355 (SECTRACK)
FEDORA-2011-7823 (FEDORA)
8238 (SREASON)
RHSA-2011:0833 (REDHAT)
http://downloads.avaya.com/css/P8/documents/100145416 (CONFIRM)
kernel-guid-dos(66773) (XF)
20110413 [PRE-SA-2011-03] Denial-of-service vulnerability in EFI partition handling code of the Linux kernel (BUGTRAQ)
CVE: CVE-2011-1585
CVE: CVE-2011-1585
Id:
CVE-2011-1585
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1585
Comment
: The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not properly determine the associations between users and sessions, which allows local users to bypass CIFS share authentication by leveraging a mount of a share by a different user.
CVSSv2 Score:
3.3
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:P/A:N
CWE:
264 (Permissions, Privileges, and Access Controls)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=697394 (CONFIRM)
[oss-security] 20110415 Re: CVE Request: cifs session reuse (MLIST)
https://github.com/torvalds/linux/commit/4ff67b720c02c36e54d55b88c2931879b7db1cd2 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36 (CONFIRM)
SUSE-SU-2015:0812 (SUSE)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4ff67b720c02c36e54d55b88c2931879b7db1cd2 (MISC)
CVE: CVE-2011-1593
CVE: CVE-2011-1593
Id:
CVE-2011-1593
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1593
Comment
: Multiple integer overflows in the next_pidmap function in kernel/pid.c in the Linux kernel before 2.6.38.4 allow local users to cause a denial of service (system crash) via a crafted (1) getdents or (2) readdir system call.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
190 (Integer Overflow or Wraparound)
References:
[oss-security] 20110420 Re: CVE request -- kernel: proc: signedness issue in next_pidmap() (MLIST)
[linux-kernel] 20110418 Re: Kernel panic (NULL ptr deref?) in find_ge_pid()/next_pidmap() (via sys_getdents or sys_readdir) (MLIST)
44164 (SECUNIA)
https://bugzilla.redhat.com/show_bug.cgi?id=697822 (CONFIRM)
1025420 (SECTRACK)
[oss-security] 20110419 CVE request -- kernel: proc: signedness issue in next_pidmap() (MLIST)
47497 (BID)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38.4 (CONFIRM)
USN-1146-1 (UBUNTU)
RHSA-2011:0927 (REDHAT)
kernel-nextpidmap-dos(66876) (XF)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c78193e9c7bcbf25b8237ad0dec82f805c4ea69b (MISC)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d8bdc59f215e62098bc5b4256fd9928bf27053a1 (MISC)
CVE: CVE-2011-1598
CVE: CVE-2011-1598
Id:
CVE-2011-1598
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1598
Comment
: The bcm_release function in net/can/bcm.c in the Linux kernel before 2.6.39-rc6 does not properly validate a socket data structure, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted release operation.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
476 (NULL Pointer Dereference)
References:
[netdev] 20110420 Add missing socket check in can/bcm release. (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110425 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110422 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.39-rc6 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=698057 (CONFIRM)
[oss-security] 20110420 CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110420 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
47503 (BID)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c6914a6f261aca0c9f715f883a353ae7ff51fe83 (MISC)
CVE: CVE-2011-1745
CVE: CVE-2011-1745
Id:
CVE-2011-1745
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1745
Comment
: Integer overflow in the agp_generic_insert_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 allows local users to gain privileges or cause a denial of service (system crash) via a crafted AGPIOC_BIND agp_ioctl ioctl call.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE:
190 (Integer Overflow or Wraparound)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38.5 (CONFIRM)
[oss-security] 20110421 CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=698996 (CONFIRM)
[oss-security] 20110422 Re: CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
[linux-kernel] 20110414 [PATCH] char: agp: fix arbitrary kernel memory writes (MLIST)
47534 (BID)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=194b3da873fd334ef183806db751473512af29ce (MISC)
CVE: CVE-2011-1746
CVE: CVE-2011-1746
Id:
CVE-2011-1746
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1746
Comment
: Multiple integer overflows in the (1) agp_allocate_memory and (2) agp_create_user_memory functions in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 allow local users to trigger buffer overflows, and consequently cause a denial of service (system crash) or possibly have unspecified other impact, via vectors related to calls that specify a large number of memory pages.
CVSSv2 Score:
6.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE:
189 (Numeric Errors)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.38.5 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=698998 (CONFIRM)
[oss-security] 20110421 CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
[oss-security] 20110422 Re: CVE request: kernel: buffer overflow and DoS issues in agp (MLIST)
[linux-kernel] 20110419 Re: [PATCH] char: agp: fix OOM and buffer overflow (MLIST)
[linux-kernel] 20110414 [PATCH] char: agp: fix OOM and buffer overflow (MLIST)
47535 (BID)
RHSA-2011:0927 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b522f02184b413955f3bc952e3776ce41edc6355 (MISC)
CVE: CVE-2011-1748
CVE: CVE-2011-1748
Id:
CVE-2011-1748
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1748
Comment
: The raw_release function in net/can/raw.c in the Linux kernel before 2.6.39-rc6 does not properly validate a socket data structure, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted release operation.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
476 (NULL Pointer Dereference)
References:
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.39-rc6 (CONFIRM)
[oss-security] 20110425 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=698057 (CONFIRM)
[oss-security] 20110422 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[oss-security] 20110421 Re: CVE request: kernel: missing socket check in can/bcm release (MLIST)
[netdev] 20110420 [PATCH v2] can: add missing socket check in can/raw release (MLIST)
47835 (BID)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=10022a6c66e199d8f61d9044543f38785713cbbd (MISC)
CVE: CVE-2011-2182
CVE: CVE-2011-2182
Id:
CVE-2011-2182
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2182
Comment
: The ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel before 2.6.39.1 does not properly handle memory allocation for non-initial fragments, which might allow local users to conduct buffer overflow attacks, and gain privileges or obtain sensitive information, via a crafted LDM partition table. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1017.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
References:
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39.1 (CONFIRM)
https://github.com/torvalds/linux/commit/cae13fe4cc3f24820ffb990c09110626837e85d4 (CONFIRM)
[oss-security] 20110605 Re: CVE request: kernel: fs/partitions: Kernel heap overflow via corrupted LDM partition tables (MLIST)
HPSBGN02970 (HP)
52334 (BID)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=cae13fe4cc3f24820ffb990c09110626837e85d4 (MISC)
CVE: CVE-2011-2183
CVE: CVE-2011-2183
Id:
CVE-2011-2183
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2183
Comment
: Race condition in the scan_get_next_rmap_item function in mm/ksm.c in the Linux kernel before 2.6.39.3, when Kernel SamePage Merging (KSM) is enabled, allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted application.
CVSSv2 Score:
4
Access vector:
LOCAL
Access complexity:
HIGH
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:H/Au:N/C:N/I:N/A:C
CWE:
362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'))
References:
https://github.com/torvalds/linux/commit/2b472611a32a72f4a118c069c2d62a1a3f087afd (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=710338 (CONFIRM)
[oss-security] 20110606 Re: CVE request: kernel: ksm: race between ksmd and exiting task (MLIST)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39.3 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=2b472611a32a72f4a118c069c2d62a1a3f087afd (MISC)
CVE: CVE-2011-2213
CVE: CVE-2011-2213
Id:
CVE-2011-2213
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2213
Comment
: The inet_diag_bc_audit function in net/ipv4/inet_diag.c in the Linux kernel before 2.6.39.3 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message, as demonstrated by an INET_DIAG_BC_JMP instruction with a zero yes value, a different vulnerability than CVE-2010-3880.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
835 (Loop with Unreachable Exit Condition ('Infinite Loop'))
References:
https://bugzilla.redhat.com/show_bug.cgi?id=714536 (CONFIRM)
[netdev] 20110601 Re: inet_diag insufficient validation? (MLIST)
[oss-security] 20110620 Re: CVE request: kernel: inet_diag: fix inet_diag_bc_audit() (MLIST)
[netdev] 20110603 Re: inet_diag insufficient validation? (MLIST)
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39.3 (CONFIRM)
[netdev] 20110617 [PATCH] inet_diag: fix inet_diag_bc_audit() (MLIST)
[oss-security] 20110620 Re: CVE request: kernel: inet_diag: fix inet_diag_bc_audit() (MLIST)
http://patchwork.ozlabs.org/patch/100857/ (CONFIRM)
[netdev] 20110601 inet_diag insufficient validation? (MLIST)
[oss-security] 20110620 CVE request: kernel: inet_diag: fix inet_diag_bc_audit() (MLIST)
RHSA-2011:0927 (REDHAT)
HPSBGN02970 (HP)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=eeb1497277d6b1a0a34ed36b97e18f2bd7d6de0d (MISC)
CVE: CVE-2011-2491
CVE: CVE-2011-2491
Id:
CVE-2011-2491
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2491
Comment
: The Network Lock Manager (NLM) protocol implementation in the NFS client functionality in the Linux kernel before 3.0 allows local users to cause a denial of service (system hang) via a LOCK_UN flock system call.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
400 (Uncontrolled Resource Consumption ('Resource Exhaustion'))
References:
[oss-security] 20110623 Re: CVE request: kernel: NLM: Don't hang forever on NLM unlock requests (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=709393 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v3.0/ChangeLog-3.0 (CONFIRM)
https://github.com/torvalds/linux/commit/0b760113a3a155269a3fba93a409c640031dd68f (CONFIRM)
RHSA-2011:1212 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0b760113a3a155269a3fba93a409c640031dd68f (MISC)
CVE: CVE-2011-2496
CVE: CVE-2011-2496
Id:
CVE-2011-2496
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2496
Comment
: Integer overflow in the vma_to_resize function in mm/mremap.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (BUG_ON and system crash) via a crafted mremap system call that expands a memory mapping.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE:
189 (Numeric Errors)
References:
https://github.com/torvalds/linux/commit/982134ba62618c2d69fbbbd166d0a11ee3b7e3d8 (CONFIRM)
[oss-security] 20110627 Re: CVE request: kernel: mm: avoid wrapping vm_pgoff in mremap() and stack expansions (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=716538 (CONFIRM)
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39 (CONFIRM)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=982134ba62618c2d69fbbbd166d0a11ee3b7e3d8 (MISC)
CVE: CVE-2011-2517
CVE: CVE-2011-2517
Id:
CVE-2011-2517
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2517
Comment
: Multiple buffer overflows in net/wireless/nl80211.c in the Linux kernel before 2.6.39.2 allow local users to gain privileges by leveraging the CAP_NET_ADMIN capability during scan operations with a long SSID value.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE:
119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
References:
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39.2 (CONFIRM)
https://bugzilla.redhat.com/show_bug.cgi?id=718152 (CONFIRM)
https://github.com/torvalds/linux/commit/208c72f4fe44fe09577e7975ba0e7fa0278f3d03 (CONFIRM)
[oss-security] 20110701 Re: CVE request: kernel: nl80211: missing check for valid SSID size in scan operations (MLIST)
RHSA-2011:1212 (REDHAT)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=208c72f4fe44fe09577e7975ba0e7fa0278f3d03 (MISC)
Content available only for registered users!
ovaldb@altx-soft.com