PT-2008-6955 · Suse+3 · Cluster-Network-Kmp-Pae+54
Ramon De Carvalho Valle
·
Publicado
1970-01-01
·
Atualizado
2023-02-13
·
CVE-2009-2406
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
SUSE Linux Enterprise kernel-default-base (affected versions not specified)
openSUSE kernel-pseries64 (affected versions not specified)
openSUSE kernel-s390-debug (affected versions not specified)
openSUSE kernel-smp-debuginfo (affected versions not specified)
SUSE Linux Enterprise kernel-default-debugsource (affected versions not specified)
SUSE Linux Enterprise kernel-pae (affected versions not specified)
openSUSE kernel-pmac64 (affected versions not specified)
SUSE Linux Enterprise cluster-network-kmp-pae (affected versions not specified)
openSUSE kexec-tools (affected versions not specified)
openSUSE appleir-kmp-debug (affected versions not specified)
SUSE Linux Enterprise kernel-pae-extra (affected versions not specified)
openSUSE kernel-xenpae (affected versions not specified)
SUSE Linux Enterprise kernel-pae-base (affected versions not specified)
openSUSE kernel-s390x (affected versions not specified)
openSUSE kernel-s390x-debug (affected versions not specified)
openSUSE kernel-64k-pagesize (affected versions not specified)
openSUSE acx-kmp-debug (affected versions not specified)
openSUSE pcc-acpi-kmp-debug (affected versions not specified)
openSUSE kexec-tools-debuginfo (affected versions not specified)
SUSE Linux Enterprise kernel-ec2-base (affected versions not specified)
openSUSE um-host-install-initrd (affected versions not specified)
openSUSE kernel-vmipae (affected versions not specified)
SUSE Linux Enterprise ext4dev-kmp-default (affected versions not specified)
openSUSE kernel-iseries64-debuginfo (affected versions not specified)
openSUSE um-host-kernel (affected versions not specified)
openSUSE kernel-smp (affected versions not specified)
SUSE Linux Enterprise ocfs2-kmp-xen (affected versions not specified)
SUSE Linux Enterprise kernel-ec2 (affected versions not specified)
SUSE Linux Enterprise ocfs2-kmp-default (affected versions not specified)
SUSE Linux Enterprise cluster-network-kmp-xen (affected versions not specified)
openSUSE kernel-um (affected versions not specified)
openSUSE uvcvideo-kmp-debug (affected versions not specified)
SUSE Linux Enterprise ext4dev-kmp-ppc64 (affected versions not specified)
openSUSE kernel-iseries64 (affected versions not specified)
SUSE Linux Enterprise kernel-default-extra (affected versions not specified)
openSUSE acerhk-kmp-debug (affected versions not specified)
openSUSE kernel-sn2 (affected versions not specified)
openSUSE kernel-s390 (affected versions not specified)
SUSE Linux Enterprise kernel-xen-base (affected versions not specified)
openSUSE wlan-ng-kmp-debug (affected versions not specified)
SUSE Linux Enterprise kexec-tools-debuginfo (affected versions not specified)
SUSE Linux Enterprise kernel-ppc64-debugsource (affected versions not specified)
openSUSE kernel-xenpae-debuginfo (affected versions not specified)
SUSE Linux Enterprise kernel-xen-extra (affected versions not specified)
SUSE Linux Enterprise kernel-kdump-debugsource (affected versions not specified)
openSUSE tpctl-kmp-debug (affected versions not specified)
SUSE Linux Enterprise cluster-network-kmp-default (affected versions not specified)
openSUSE kernel-bigsmp (affected versions not specified)
openSUSE gspcav-kmp-debug (affected versions not specified)
SUSE Linux Enterprise ocfs2-kmp-pae (affected versions not specified)
openSUSE nouveau-kmp-debug (affected versions not specified)
openSUSE kernel-bigsmp-debuginfo (affected versions not specified)
SUSE Linux Enterprise kernel-ppc64-base (affected versions not specified)
openSUSE at76 usb-kmp-debug (affected versions not specified)
openSUSE atl2-kmp-debug (affected versions not specified)
Description
The issue involves multiple vulnerabilities in various kernel packages of SUSE Linux Enterprise and openSUSE operating systems. These vulnerabilities can be exploited remotely, potentially leading to a denial of service (system crash) or possibly gaining privileges. The vulnerabilities are related to the eCryptfs subsystem in the Linux kernel, specifically a stack-based buffer overflow in the parse tag 11 packet function. This can be caused by crafted eCryptfs files, allowing local users to exploit the vulnerability.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux Kernel
Red Hat
Acerhk-Kmp-Debug
Acx-Kmp-Debug
Appleir-Kmp-Debug
At76 Usb-Kmp-Debug
Atl2-Kmp-Debug
Cluster-Network-Kmp-Default
Cluster-Network-Kmp-Pae
Cluster-Network-Kmp-Xen
Ecryptfs
Ext4Dev-Kmp-Default
Ext4Dev-Kmp-Ppc64
Gspcav-Kmp-Debug
Kernel-64K-Pagesize
Kernel-Bigsmp
Kernel-Bigsmp-Debuginfo
Kernel-Default-Base
Kernel-Default-Debugsource
Kernel-Default-Extra
Kernel-Ec2
Kernel-Ec2-Base
Kernel-Iseries64
Kernel-Iseries64-Debuginfo
Kernel-Kdump-Debugsource
Kernel-Pae
Kernel-Pae-Base
Kernel-Pae-Extra
Kernel-Pmac64
Kernel-Ppc64-Base
Kernel-Ppc64-Debugsource
Kernel-Pseries64
Kernel-S390X
Kernel-S390X-Debug
Kernel-Smp
Kernel-Smp-Debuginfo
Kernel-Sn2
Kernel-Um
Kernel-Vmipae
Kernel-Xen-Base
Kernel-Xen-Extra
Kernel-Xenpae
Kernel-Xenpae-Debuginfo
Kexec-Tools
Kexec-Tools-Debuginfo
Nouveau-Kmp-Debug
Ocfs2-Kmp-Default
Ocfs2-Kmp-Pae
Ocfs2-Kmp-Xen
Pcc-Acpi-Kmp-Debug
Tpctl-Kmp-Debug
Um-Host-Install-Initrd
Um-Host-Kernel
Uvcvideo-Kmp-Debug
Wlan-Ng-Kmp-Debug