PT-2014-1791 · Linux+3 · Udisks+3

Florian Weimer

·

Published

2014-01-22

·

Updated

2024-06-15

·

CVE-2014-0004

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions udisks versions 1.0.1 through 1.0.4 udisks versions 2.x prior to 2.1.3 udisks-devel version 1.0.1 udisks-devel-docs version 1.0.1 udisks-debuginfo version 1.0.1
Description The issue is related to a stack-based buffer overflow in udisks, which can be exploited locally to cause a denial of service or possibly execute arbitrary code via a long mount point. This can lead to a disruption of confidentiality, integrity, and availability of protected information. The exploitation can be carried out by a local attacker.
Recommendations For udisks versions 1.0.1 through 1.0.4, update to version 1.0.5 or later. For udisks versions 2.x prior to 2.1.3, update to version 2.1.3 or later. For udisks-devel version 1.0.1, update to a version that includes the fix for this issue. For udisks-devel-docs version 1.0.1, update to a version that includes the fix for this issue. For udisks-debuginfo version 1.0.1, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the udisks package to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1076
BDU:2015-04124
BDU:2015-06955
BDU:2015-06956
BDU:2015-06957
BDU:2015-06958
BDU:2015-09083
BDU:2015-09084
BDU:2015-09085
BDU:2015-09086
BDU:2015-09758
CESA-2014_0293
CVE-2014-0004
DSA-2872-1
MGASA-2014-0129
OPENSUSE-SU-2024:10408-1
OPENSUSE-SU-2024:10495-1
RHSA-2014:0293
RHSA-2014_0293

Affected Products

Alt Linux
Centos
Red Hat
Udisks