Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2008-3528

Опубликовано: 27 сент. 2008
Источник: debian
EPSS Низкий

Описание

The error-reporting functionality in (1) fs/ext2/dir.c, (2) fs/ext3/dir.c, and possibly (3) fs/ext4/dir.c in the Linux kernel 2.6.26.5 does not limit the number of printk console messages that report directory corruption, which allows physically proximate attackers to cause a denial of service (temporary system hang) by mounting a filesystem that has corrupted dir->i_size and dir->i_blocks values and performing (a) read or (b) write operations. NOTE: there are limited scenarios in which this crosses privilege boundaries.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linux-2.6fixed2.6.26-11package
linux-2.6.24fixed2.6.24-6~etchnhalf.7package

Примечания

  • cdbf6dba28e8e6268c8420857696309470009fd9 (ext3)

  • bd39597cbd42a784105a04010100e27267481c67 (ext2)

  • 9d9f177572d9e4eba0f2e18523b44f90dd51fe74 (ext4)

  • Comment from tytso:

  • Note: some people thinks this represents a security bug, since it

  • might make the system go away while it is printing a large number of

  • console messages, especially if a serial console is involved. Hence,

  • it has been assigned CVE-2008-3528, but it requires that the attacker

  • either has physical access to your machine to insert a USB disk with a

  • corrupted filesystem image (at which point why not just hit the power

  • button), or is otherwise able to convince the system administrator to

  • mount an arbitrary filesystem image (at which point why not just

  • include a setuid shell or world-writable hard disk device file or some

  • such). Me, I think they're just being silly.

EPSS

Процентиль: 57%
0.00352
Низкий

Связанные уязвимости

ubuntu
больше 16 лет назад

The error-reporting functionality in (1) fs/ext2/dir.c, (2) fs/ext3/dir.c, and possibly (3) fs/ext4/dir.c in the Linux kernel 2.6.26.5 does not limit the number of printk console messages that report directory corruption, which allows physically proximate attackers to cause a denial of service (temporary system hang) by mounting a filesystem that has corrupted dir->i_size and dir->i_blocks values and performing (a) read or (b) write operations. NOTE: there are limited scenarios in which this crosses privilege boundaries.

redhat
почти 17 лет назад

The error-reporting functionality in (1) fs/ext2/dir.c, (2) fs/ext3/dir.c, and possibly (3) fs/ext4/dir.c in the Linux kernel 2.6.26.5 does not limit the number of printk console messages that report directory corruption, which allows physically proximate attackers to cause a denial of service (temporary system hang) by mounting a filesystem that has corrupted dir->i_size and dir->i_blocks values and performing (a) read or (b) write operations. NOTE: there are limited scenarios in which this crosses privilege boundaries.

nvd
больше 16 лет назад

The error-reporting functionality in (1) fs/ext2/dir.c, (2) fs/ext3/dir.c, and possibly (3) fs/ext4/dir.c in the Linux kernel 2.6.26.5 does not limit the number of printk console messages that report directory corruption, which allows physically proximate attackers to cause a denial of service (temporary system hang) by mounting a filesystem that has corrupted dir->i_size and dir->i_blocks values and performing (a) read or (b) write operations. NOTE: there are limited scenarios in which this crosses privilege boundaries.

github
около 3 лет назад

The error-reporting functionality in (1) fs/ext2/dir.c, (2) fs/ext3/dir.c, and possibly (3) fs/ext4/dir.c in the Linux kernel 2.6.26.5 does not limit the number of printk console messages that report directory corruption, which allows physically proximate attackers to cause a denial of service (temporary system hang) by mounting a filesystem that has corrupted dir->i_size and dir->i_blocks values and performing (a) read or (b) write operations. NOTE: there are limited scenarios in which this crosses privilege boundaries.

oracle-oval
около 16 лет назад

ELSA-2009-0326: kernel security and bug fix update (IMPORTANT)

EPSS

Процентиль: 57%
0.00352
Низкий