PT-2001-2689 · Red Hat+2 · Losetup+4
Published
1970-01-01
·
Updated
2016-12-08
·
CVE-2001-1399
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Debian GNU/Linux kernel-image-2.2.19 versions prior to 2.2.19
Red Hat Linux mount versions 2.10r-0.6.x
Red Hat Linux mount versions 2.10r-5
Red Hat Linux losetup versions 2.10r-0.6.x
Red Hat Linux losetup versions 2.10r-5
Red Hat Linux nfs-utils version 0.3.1
Description
The issue affects multiple packages in Debian GNU/Linux and Red Hat Linux, allowing remote exploitation that may lead to a breach of confidentiality, integrity, and availability of protected information. Certain operations in the Linux kernel before version 2.2.19 on the x86 architecture copy the wrong number of bytes, which might allow attackers to modify memory.
Recommendations
For Debian GNU/Linux kernel-image-2.2.19 versions prior to 2.2.19, update to a version 2.2.19 or later.
For Red Hat Linux mount versions 2.10r-0.6.x and 2.10r-5, update to a version later than 2.10r-5.
For Red Hat Linux losetup versions 2.10r-0.6.x and 2.10r-5, update to a version later than 2.10r-5.
For Red Hat Linux nfs-utils version 0.3.1, update to a version later than 0.3.1.
As a temporary workaround, consider restricting access to the vulnerable components until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linux Kernel
Losetup
Mount
Nfs-Utils