PT-2014-1791 · Linux+3 · Udisks+3
Florian Weimer
·
Published
2014-01-22
·
Updated
2024-06-15
·
CVE-2014-0004
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
udisks versions 1.0.1 through 1.0.4
udisks versions 2.x prior to 2.1.3
udisks-devel version 1.0.1
udisks-devel-docs version 1.0.1
udisks-debuginfo version 1.0.1
Description
The issue is related to a stack-based buffer overflow in udisks, which can be exploited locally to cause a denial of service or possibly execute arbitrary code via a long mount point. This can lead to a disruption of confidentiality, integrity, and availability of protected information. The exploitation can be carried out by a local attacker.
Recommendations
For udisks versions 1.0.1 through 1.0.4, update to version 1.0.5 or later.
For udisks versions 2.x prior to 2.1.3, update to version 2.1.3 or later.
For udisks-devel version 1.0.1, update to a version that includes the fix for this issue.
For udisks-devel-docs version 1.0.1, update to a version that includes the fix for this issue.
For udisks-debuginfo version 1.0.1, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the
udisks package to minimize the risk of exploitation.Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Red Hat
Udisks