Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-0758

Опубликовано: 12 мая 2016
Источник: redhat
CVSS2: 7.2
EPSS Низкий

Описание

Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data.

A flaw was found in the way the Linux kernel's ASN.1 DER decoder processed certain certificate files with tags of indefinite length. A local, unprivileged user could use a specially crafted X.509 certificate DER file to crash the system or, potentially, escalate their privileges on the system.

Отчет

This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 and 6. This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 7 and Red Hat Enterprise MRG 2.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2016:105112.05.2016
Red Hat Enterprise Linux 7kernelFixedRHSA-2016:103312.05.2016
Red Hat Enterprise MRG 2kernel-rtFixedRHSA-2016:105512.05.2016

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=1300257kernel: tags with indefinite length can corrupt pointers in asn1_find_indefinite_length()

EPSS

Процентиль: 32%
0.00122
Низкий

7.2 High

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 9 лет назад

Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data.

CVSS3: 7.8
nvd
почти 9 лет назад

Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data.

CVSS3: 7.8
debian
почти 9 лет назад

Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 ...

CVSS3: 7.8
github
около 3 лет назад

Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data.

oracle-oval
около 9 лет назад

ELSA-2016-1033: kernel security and bug fix update (IMPORTANT)

EPSS

Процентиль: 32%
0.00122
Низкий

7.2 High

CVSS2