CVE-2009-0269


Published: 26-01-2009
Updated: 29-01-2009

Product:
linux: kernel 2.2.27
linux: kernel 2.4.36
linux: kernel 2.4.36.1
linux: kernel 2.4.36.2
linux: kernel 2.4.36.3
linux: kernel 2.4.36.4
linux: kernel 2.4.36.5
linux: kernel 2.4.36.6
linux: kernel 2.6
linux: kernel 2.6.18
linux: kernel 2.6.18
linux: kernel 2.6.18
linux: kernel 2.6.18
linux: kernel 2.6.18
linux: kernel 2.6.18
linux: kernel 2.6.18
linux: kernel 2.6.19.4
linux: kernel 2.6.19.5
linux: kernel 2.6.19.6
linux: kernel 2.6.19.7
linux: kernel 2.6.20.16
linux: kernel 2.6.20.17
linux: kernel 2.6.20.18
linux: kernel 2.6.20.19
linux: kernel 2.6.20.20
linux: kernel 2.6.20.21
linux: kernel 2.6.21.5
linux: kernel 2.6.21.6
linux: kernel 2.6.21.7
linux: kernel 2.6.22
linux: kernel 2.6.22.1
linux: kernel 2.6.22.10
linux: kernel 2.6.22.11
linux: kernel 2.6.22.12
linux: kernel 2.6.22.13
linux: kernel 2.6.22.14
linux: kernel 2.6.22.15
linux: kernel 2.6.22.17
linux: kernel 2.6.22.18
linux: kernel 2.6.22.19
linux: kernel 2.6.22.2
linux: kernel 2.6.22.20
linux: kernel 2.6.22.21
linux: kernel 2.6.22.22
linux: kernel 2.6.22.8
linux: kernel 2.6.22.9
linux: kernel 2.6.22_rc1
linux: kernel 2.6.22_rc7
linux: kernel 2.6.23
linux: kernel 2.6.23.10
linux: kernel 2.6.23.11
linux: kernel 2.6.23.12
linux: kernel 2.6.23.13
linux: kernel 2.6.23.15
linux: kernel 2.6.23.16
linux: kernel 2.6.23.17
linux: kernel 2.6.23.8
linux: kernel 2.6.23.9
linux: kernel 2.6.23_rc1
linux: kernel 2.6.24
linux: kernel 2.6.24.1
linux: kernel 2.6.24.2
linux: kernel 2.6.24.3
linux: kernel 2.6.24.4
linux: kernel 2.6.24.5
linux: kernel 2.6.24.6
linux: kernel 2.6.24.7
linux: kernel 2.6.24_rc1
linux: kernel 2.6.24_rc4
linux: kernel 2.6.24_rc5
linux: kernel 2.6.25
linux: kernel 2.6.25
linux: kernel 2.6.25.1
linux: kernel 2.6.25.1
linux: kernel 2.6.25.10
linux: kernel 2.6.25.10
linux: kernel 2.6.25.11
linux: kernel 2.6.25.11
linux: kernel 2.6.25.12
linux: kernel 2.6.25.12
linux: kernel 2.6.25.13
linux: kernel 2.6.25.14
linux: kernel 2.6.25.15
linux: kernel 2.6.25.16
linux: kernel 2.6.25.17
linux: kernel 2.6.25.2
linux: kernel 2.6.25.2
linux: kernel 2.6.25.3
linux: kernel 2.6.25.3
linux: kernel 2.6.25.4
linux: kernel 2.6.25.4
linux: kernel 2.6.25.5
linux: kernel 2.6.25.5
linux: kernel 2.6.25.6
linux: kernel 2.6.25.6
linux: kernel 2.6.25.7
linux: kernel 2.6.25.7
linux: kernel 2.6.25.8
linux: kernel 2.6.25.8
linux: kernel 2.6.25.9
linux: kernel 2.6.25.9
linux: kernel 2.6.26
linux: kernel 2.6.26.1
linux: kernel 2.6.26.2
linux: kernel 2.6.26.3
linux: kernel 2.6.26.4
linux: kernel 2.6.26.5
linux: kernel 2.6.27
linux: kernel 2.6.28

Severity: Medium (4.9)

CVSS vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C)

Attack`s vector: Localy exploitable

Potential loss type: Availability

Vulnerability description:
fs/ecryptfs/inode.c in the eCryptfs subsystem in the Linux kernel before 2.6.28.1 allows local users to cause a denial of service (fault or memory corruption), or possibly have unspecified other impact, via a readlink call that results in an error, leading to use of a -1 return value as an array index.

Patch available: Yes

References:
BID: http://www.securityfocus.com/bid/33412
MLIST: https://lists.launchpad.net/ecryptfs-devel/msg00011.html
MLIST: https://lists.launchpad.net/ecryptfs-devel/msg00010.html
XF: http://xforce.iss.net/xforce/xfdb/48188
CONFIRM: http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.1
CONFIRM: http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git;a=...

Cisco IOS Software Resource Reservation Protocol Interface Queue Wedge Vulnerability

A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software an...

30 september, 2013

Cisco IOS Software Internet Key Exchange Memory Leak Vulnerability

A vulnerability in the Internet Key Exchange (IKE) protocol of Cisco IOS Software and Cisco ...

30 september, 2013

Cisco IOS Software Multicast Network Time Protocol Denial of Service Vulnerability

A vulnerability in the implementation of the Network Time Protocol (NTP) feature in Cisco IO...

30 september, 2013

MS14-035: Cumulative Security Update for Internet Explorer (2969262)

This security update resolves two publicly disclosed vulnerabilities and fifty-seven privately repor...

11 june, 2014

MS14-036: Vulnerabilities in Microsoft Graphics Component Could Allow Remote Code Execution (2967487)

This security update resolves two privately reported vulnerabilities in Microsoft Windows, Microsoft...

11 june, 2014

MS14-034: Vulnerability in Microsoft Word Could Allow Remote Code Execution (2969261)

This security update resolves one privately reported vulnerability in Microsoft Office.

10 june, 2014

CVE-2014-8678

The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename, related to "saveFile."

CVE-2014-8558

JExperts Channel Platform 5.0.33_CCB allows remote authenticated users to bypass access restrictions via crafted action and key parameters.

CVE-2014-8420

The ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before 7.2 SP2, and SonicWALL UMA before 7.2 SP2 allows remote authenticated users to execute arbitrary code via unspecified vectors.

CVE-2014-8368

The web interface in Aruba Networks AirWave before 7.7.14 and 8.x before 8.0.5 allows remote authenticated users to gain privileges and execute arbitrary commands via unspecified vectors.

CVE-2014-8367

SQL injection vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) 6.2.x, 6.3.x before 6.3.6, and 6.4.x before 6.4.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2014-8004

Cisco IOS XR allows remote attackers to cause a denial of service (LISP process reload) by establishing many LISP TCP sessions, aka Bug ID CSCuq90378.

CVE-2014-8002

Use-after-free vulnerability in decode_slice.cpp in Cisco OpenH264 1.2.0 and earlier allows remote attackers to execute arbitrary code via an encoded media file.

CVE-2014-8001

Buffer overflow in decode.cpp in Cisco OpenH264 1.2.0 and earlier allows remote attackers to execute arbitrary code via an encoded media file.

CVE-2014-7839

DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.

CVE-2014-3605

** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2014-6407.  Reason: This candidate is a reservation duplicate of CVE-2014-6407.  Notes: All CVE users should reference CVE-2014-6407 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.

CVE-2014-1421

mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.

CVE-2014-9016

The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.

CVE-2014-9015

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

CVE-2014-8991

pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.

CVE-2014-8988

MantisBT before 1.2.18 allows remote authenticated users to bypass the $g_download_attachments_threshold and $g_view_attachments_threshold restrictions and read attachments for private projects by leveraging access to a project that does not restrict access to attachments and a request to the download URL.

This Alert covers CVE-2010-0896 for the mail component of the Sun Convergence product

This Sun Alert covers CVE-2010-0896 for the mail component of the Sun Convergence product.

14 april, 2010

This Alert Covers CVE-2010-0893 for the Mail Component of the Sun Convergence Product

This Alert covers CVE-2010-0893 for the mail component of the Sun Convergence product.

14 april, 2010

SunOS 5.10_x86: ucode driver patch

6905530 processor microcode code can panic when retrieving microcode revision.

02 february, 2010

[RHSA-2010:1003-01] Moderate: git security update

Red Hat Security Advisory - Moderate: git security update

21 december, 2010

[RHSA-2010:1002-01] Moderate: mod_auth_mysql security update

Red Hat Security Advisory - Moderate: mod_auth_mysql security update

21 december, 2010

[RHSA-2010:1000-01] Important: bind security update

Red Hat Security Advisory - Important: bind security update

20 december, 2010