PT-2012-2256 · Linux+3 · Linux Kernel+3

Wang Xi

·

Publicado

2012-01-13

·

Atualizado

2023-02-13

·

CVE-2012-0038

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.1.9
Description The issue is caused by an integer overflow in the xfs acl from disk function, which can lead to a heap-based buffer overflow when a local user interacts with a filesystem containing a malformed ACL, resulting in a denial of service (panic).
Recommendations For Linux kernel versions prior to 3.1.9, update to version 3.1.9 or later to resolve the issue.

Correção

DoS

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2012_0350
CVE-2012-0038
RHSA-2012:0333
RHSA-2012:0350
RHSA-2012:1042
RHSA-2012_0350
USN-1212-1
USN-1356-1
USN-1361-1
USN-1362-1
USN-1363-1
USN-1364-1
USN-1384-1
USN-1386-1
USN-1387-1
USN-1388-1
USN-1389-1
USN-1391-1
USN-1394-1

Produtos afetados

Centos
Linux Kernel
Red Hat
Suse