Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-5011

Опубликовано: 11 июл. 2016
Источник: redhat
CVSS3: 4.6
CVSS2: 4.9
EPSS Низкий

Описание

The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate attackers to cause a denial of service (memory consumption) via a crafted MSDOS partition table with an extended partition boot record at zero offset.

It was found that util-linux's libblkid library did not properly handle Extended Boot Record (EBR) partitions when reading MS-DOS partition tables. An attacker with physical USB access to a protected machine could insert a storage device with a specially crafted partition table that could, for example, trigger an infinite loop in systemd-udevd, resulting in a denial of service on that machine.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5util-linuxWill not fix
Red Hat Enterprise Linux 6util-linux-ngWill not fix
Red Hat Enterprise Linux 7util-linuxFixedRHSA-2016:260503.11.2016

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1349741util-linux: Extended partition loop in MBR partition table leads to DOS

EPSS

Процентиль: 43%
0.00203
Низкий

4.6 Medium

CVSS3

4.9 Medium

CVSS2

Связанные уязвимости

CVSS3: 4.6
ubuntu
больше 8 лет назад

The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate attackers to cause a denial of service (memory consumption) via a crafted MSDOS partition table with an extended partition boot record at zero offset.

CVSS3: 4.6
nvd
больше 8 лет назад

The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate attackers to cause a denial of service (memory consumption) via a crafted MSDOS partition table with an extended partition boot record at zero offset.

CVSS3: 4.6
debian
больше 8 лет назад

The parse_dos_extended function in partitions/dos.c in the libblkid li ...

suse-cvrf
больше 8 лет назад

Security update for util-linux

suse-cvrf
почти 9 лет назад

Security update for util-linux

EPSS

Процентиль: 43%
0.00203
Низкий

4.6 Medium

CVSS3

4.9 Medium

CVSS2