PT-2014-8348 · Linux+5 · Linux Kernel+5

Publicado

2014-10-13

·

Atualizado

2020-08-14

·

CVE-2014-7970

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.18
Description The issue is related to the pivot root implementation in the Linux kernel, which does not properly handle certain locations of a chroot directory. This allows local users to cause a denial of service, resulting in a mount-tree loop, by providing . (dot) values in both arguments to the pivot root() system call.
Recommendations For Linux kernel versions prior to 3.18, update to version 3.18 or later to resolve the issue.

Exploit

Correção

DoS

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-2297
ALT-PU-2015-1794
CESA-2017_1842
CVE-2014-7970
MGASA-2014-0451
MGASA-2014-0452
MGASA-2014-0453
MGASA-2014-0454
MGASA-2014-0455
MGASA-2014-0456
MGASA-2014-0459
MGASA-2014-0479
MGASA-2015-0075
MGASA-2015-0076
MGASA-2015-0077
MGASA-2015-0078
RHSA-2017:1842
RHSA-2017:2077
RHSA-2017_1842
RHSA-2017_2077
SUSE-RU-2015:0621-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2419-1
USN-2420-1
USN-2447-1
USN-2447-2
USN-2448-1
USN-2513-1
USN-2514-1

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu