PT-2001-2683 · Red Hat+2 · Nfs-Utils-0.3.1+6

Published

1970-01-01

·

Updated

2016-12-08

·

CVE-2001-1393

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Debian GNU/Linux kernel-image-2.2.19 versions prior to 2.2.19 Debian GNU/Linux kernel-image-2.2.19-amiga version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-atari version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-bvme6000 version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-chrp version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-compact version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-generic version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-ide version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-idepci version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-jensen version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-mac version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-mvme147 version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-mvme16x version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-nautilus version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-pmac version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-prep version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-smp version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-sun4cdm version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-sun4dm-pci version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-sun4dm-smp version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-sun4u version 2.2.19 Debian GNU/Linux kernel-image-2.2.19-sun4u-smp version 2.2.19 Red Hat Linux mount-2.10r-0.6.x version 2.10r-0.6.x Red Hat Linux mount-2.10r-5 version 2.10r-5 Red Hat Linux losetup-2.10r-0.6.x version 2.10r-0.6.x Red Hat Linux losetup-2.10r-5 version 2.10r-5 Red Hat Linux nfs-utils-0.3.1 version 0.3.1
Description The issue affects multiple packages in Debian GNU/Linux and Red Hat Linux, potentially leading to confidentiality, integrity, and availability breaches. Exploitation can be done remotely. According to Mitre, there is an unknown vulnerability in the classifier code for Linux kernel before 2.2.19, which could result in a denial of service (hang).
Recommendations As a temporary workaround, consider disabling the vulnerable kernel-image packages until a patch is available. Restrict access to the vulnerable mount, losetup, and nfs-utils packages to minimize the risk of exploitation. Avoid using the vulnerable kernel-image packages in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03682
BDU:2015-03683
BDU:2015-03684
BDU:2015-03685
BDU:2015-03686
BDU:2015-03687
BDU:2015-03688
BDU:2015-03689
BDU:2015-03690
BDU:2015-03691
BDU:2015-03692
BDU:2015-03693
BDU:2015-03694
BDU:2015-03695
BDU:2015-03696
BDU:2015-03697
BDU:2015-03698
BDU:2015-03699
BDU:2015-03700
BDU:2015-03701
BDU:2015-03702
BDU:2015-03703
BDU:2015-03704
BDU:2015-03705
BDU:2015-03706
BDU:2015-03707
BDU:2015-03708
BDU:2015-03709
BDU:2015-08156
BDU:2015-08157
BDU:2015-08165
BDU:2015-08166
BDU:2015-08173
CVE-2001-1393

Affected Products

Debian
Linux
Red Hat
Kernel-Image-2.2.19
Losetup-2.10R
Mount-2.10R
Nfs-Utils-0.3.1