Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-2407

Опубликовано: 28 июл. 2009
Источник: redhat
CVSS2: 7.2
EPSS Низкий

Описание

Heap-based buffer overflow in the parse_tag_3_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving a crafted eCryptfs file, related to a large encrypted key size in a Tag 3 packet.

Отчет

The Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, and Red Hat Enterprise MRG did not include support for eCryptfs, and therefore are not affected by this issue.

Дополнительная информация

Статус:

Important
Дефект:
CWE-130->CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=512885kernel: ecryptfs heap overflow in parse_tag_3_packet()

EPSS

Процентиль: 51%
0.00281
Низкий

7.2 High

CVSS2

Связанные уязвимости

ubuntu
почти 16 лет назад

Heap-based buffer overflow in the parse_tag_3_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving a crafted eCryptfs file, related to a large encrypted key size in a Tag 3 packet.

nvd
почти 16 лет назад

Heap-based buffer overflow in the parse_tag_3_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving a crafted eCryptfs file, related to a large encrypted key size in a Tag 3 packet.

debian
почти 16 лет назад

Heap-based buffer overflow in the parse_tag_3_packet function in fs/ec ...

github
около 3 лет назад

Heap-based buffer overflow in the parse_tag_3_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving a crafted eCryptfs file, related to a large encrypted key size in a Tag 3 packet.

oracle-oval
почти 16 лет назад

ELSA-2009-1193: kernel security and bug fix update (IMPORTANT)

EPSS

Процентиль: 51%
0.00281
Низкий

7.2 High

CVSS2

Уязвимость CVE-2009-2407