PT-2010-5700 · Linux+2 · Linux Kernel+3
Publicado
1970-01-01
·
Atualizado
2024-06-15
·
CVE-2010-3081
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
SUSE Linux Enterprise cpint-kmp-default (affected versions not specified)
Red Hat Enterprise Linux kernel-smp-2.4.21
Red Hat Enterprise Linux kernel-source-2.4.21
Red Hat Enterprise Linux kernel-hugemem-unsupported-2.4.21
Red Hat Enterprise Linux kernel-2.4.21
Red Hat Enterprise Linux kernel-doc-2.4.21
Red Hat Enterprise Linux kernel-smp-unsupported-2.4.21
Red Hat Enterprise Linux kernel-BOOT-2.4.21
Red Hat Enterprise Linux kernel-unsupported-2.4.21
Red Hat Enterprise Linux kernel-hugemem-2.4.21
Linux kernel versions prior to 2.6.36-rc4-git2
Description
The issue involves multiple vulnerabilities in various Linux kernel packages, which can lead to disruptions in confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be carried out locally or remotely, depending on the specific package and system configuration. In some cases, exploitation can allow local users to gain privileges. The compat alloc user space functions in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate userspace memory required for the 32-bit compatibility layer, which can be exploited to control a certain length value, related to a "stack pointer underflow" issue.
Recommendations
For SUSE Linux Enterprise cpint-kmp-default, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Red Hat Enterprise Linux kernel-smp-2.4.21, consider updating to a version that is not vulnerable.
For Red Hat Enterprise Linux kernel-source-2.4.21, consider updating to a version that is not vulnerable.
For Red Hat Enterprise Linux kernel-hugemem-unsupported-2.4.21, consider updating to a version that is not vulnerable.
For Red Hat Enterprise Linux kernel-2.4.21, consider updating to a version that is not vulnerable.
For Red Hat Enterprise Linux kernel-doc-2.4.21, consider updating to a version that is not vulnerable.
For Red Hat Enterprise Linux kernel-smp-unsupported-2.4.21, consider updating to a version that is not vulnerable.
For Red Hat Enterprise Linux kernel-BOOT-2.4.21, consider updating to a version that is not vulnerable.
For Red Hat Enterprise Linux kernel-unsupported-2.4.21, consider updating to a version that is not vulnerable.
For Red Hat Enterprise Linux kernel-hugemem-2.4.21, consider updating to a version that is not vulnerable.
For Linux kernel versions prior to 2.6.36-rc4-git2, consider updating to version 2.6.36-rc4-git2 or later.
Exploit
Buffer Overflow
Improper Validation of Array Index
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux Kernel
Red Hat
Suse Linux Enterprise
Suse