CVE-2009-0269


Published: 26-01-2009
Updated: 29-01-2009

Product:
linux: kernel 2.2.27
linux: kernel 2.4.36
linux: kernel 2.4.36.1
linux: kernel 2.4.36.2
linux: kernel 2.4.36.3
linux: kernel 2.4.36.4
linux: kernel 2.4.36.5
linux: kernel 2.4.36.6
linux: kernel 2.6
linux: kernel 2.6.18
linux: kernel 2.6.18
linux: kernel 2.6.18
linux: kernel 2.6.18
linux: kernel 2.6.18
linux: kernel 2.6.18
linux: kernel 2.6.18
linux: kernel 2.6.19.4
linux: kernel 2.6.19.5
linux: kernel 2.6.19.6
linux: kernel 2.6.19.7
linux: kernel 2.6.20.16
linux: kernel 2.6.20.17
linux: kernel 2.6.20.18
linux: kernel 2.6.20.19
linux: kernel 2.6.20.20
linux: kernel 2.6.20.21
linux: kernel 2.6.21.5
linux: kernel 2.6.21.6
linux: kernel 2.6.21.7
linux: kernel 2.6.22
linux: kernel 2.6.22.1
linux: kernel 2.6.22.10
linux: kernel 2.6.22.11
linux: kernel 2.6.22.12
linux: kernel 2.6.22.13
linux: kernel 2.6.22.14
linux: kernel 2.6.22.15
linux: kernel 2.6.22.17
linux: kernel 2.6.22.18
linux: kernel 2.6.22.19
linux: kernel 2.6.22.2
linux: kernel 2.6.22.20
linux: kernel 2.6.22.21
linux: kernel 2.6.22.22
linux: kernel 2.6.22.8
linux: kernel 2.6.22.9
linux: kernel 2.6.22_rc1
linux: kernel 2.6.22_rc7
linux: kernel 2.6.23
linux: kernel 2.6.23.10
linux: kernel 2.6.23.11
linux: kernel 2.6.23.12
linux: kernel 2.6.23.13
linux: kernel 2.6.23.15
linux: kernel 2.6.23.16
linux: kernel 2.6.23.17
linux: kernel 2.6.23.8
linux: kernel 2.6.23.9
linux: kernel 2.6.23_rc1
linux: kernel 2.6.24
linux: kernel 2.6.24.1
linux: kernel 2.6.24.2
linux: kernel 2.6.24.3
linux: kernel 2.6.24.4
linux: kernel 2.6.24.5
linux: kernel 2.6.24.6
linux: kernel 2.6.24.7
linux: kernel 2.6.24_rc1
linux: kernel 2.6.24_rc4
linux: kernel 2.6.24_rc5
linux: kernel 2.6.25
linux: kernel 2.6.25
linux: kernel 2.6.25.1
linux: kernel 2.6.25.1
linux: kernel 2.6.25.10
linux: kernel 2.6.25.10
linux: kernel 2.6.25.11
linux: kernel 2.6.25.11
linux: kernel 2.6.25.12
linux: kernel 2.6.25.12
linux: kernel 2.6.25.13
linux: kernel 2.6.25.14
linux: kernel 2.6.25.15
linux: kernel 2.6.25.16
linux: kernel 2.6.25.17
linux: kernel 2.6.25.2
linux: kernel 2.6.25.2
linux: kernel 2.6.25.3
linux: kernel 2.6.25.3
linux: kernel 2.6.25.4
linux: kernel 2.6.25.4
linux: kernel 2.6.25.5
linux: kernel 2.6.25.5
linux: kernel 2.6.25.6
linux: kernel 2.6.25.6
linux: kernel 2.6.25.7
linux: kernel 2.6.25.7
linux: kernel 2.6.25.8
linux: kernel 2.6.25.8
linux: kernel 2.6.25.9
linux: kernel 2.6.25.9
linux: kernel 2.6.26
linux: kernel 2.6.26.1
linux: kernel 2.6.26.2
linux: kernel 2.6.26.3
linux: kernel 2.6.26.4
linux: kernel 2.6.26.5
linux: kernel 2.6.27
linux: kernel 2.6.28

Severity: Medium (4.9)

CVSS vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C)

Attack`s vector: Localy exploitable

Potential loss type: Availability

Vulnerability description:
fs/ecryptfs/inode.c in the eCryptfs subsystem in the Linux kernel before 2.6.28.1 allows local users to cause a denial of service (fault or memory corruption), or possibly have unspecified other impact, via a readlink call that results in an error, leading to use of a -1 return value as an array index.

Patch available: Yes

References:
BID: http://www.securityfocus.com/bid/33412
MLIST: https://lists.launchpad.net/ecryptfs-devel/msg00011.html
MLIST: https://lists.launchpad.net/ecryptfs-devel/msg00010.html
XF: http://xforce.iss.net/xforce/xfdb/48188
CONFIRM: http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.1
CONFIRM: http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git;a=...

Cisco IOS Software Resource Reservation Protocol Interface Queue Wedge Vulnerability

A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software an...

30 september, 2013

Cisco IOS Software Internet Key Exchange Memory Leak Vulnerability

A vulnerability in the Internet Key Exchange (IKE) protocol of Cisco IOS Software and Cisco ...

30 september, 2013

Cisco IOS Software Multicast Network Time Protocol Denial of Service Vulnerability

A vulnerability in the implementation of the Network Time Protocol (NTP) feature in Cisco IO...

30 september, 2013

MS14-035: Cumulative Security Update for Internet Explorer (2969262)

This security update resolves two publicly disclosed vulnerabilities and fifty-seven privately repor...

11 june, 2014

MS14-036: Vulnerabilities in Microsoft Graphics Component Could Allow Remote Code Execution (2967487)

This security update resolves two privately reported vulnerabilities in Microsoft Windows, Microsoft...

11 june, 2014

MS14-034: Vulnerability in Microsoft Word Could Allow Remote Code Execution (2969261)

This security update resolves one privately reported vulnerability in Microsoft Office.

10 june, 2014

CVE-2014-4726

Unspecified vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.8 for WordPress has unspecified impact and attack vectors.

CVE-2014-4725

The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.

CVE-2014-4979

Apple QuickTime allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed version number and flags in an mvhd atom.

CVE-2014-4971

Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted address in an IOCTL call, related to (1) the MQAC.sys driver in the MQ Access Control subsystem and (2) the BthPan.sys driver in the Bluetooth Personal Area Networking subsystem.

CVE-2014-4858

Multiple SQL injection vulnerabilities in CWPLogin.aspx in Sabre AirCentre Crew products 2010.2.12.20008 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.

CVE-2014-4857

Cross-site scripting (XSS) vulnerability in Gurock TestRail before 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the Created By field in a project activity.

CVE-2014-4748

Cross-site scripting (XSS) vulnerability in the Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVE-2014-4747

The Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows physically proximate attackers to discover a meeting password hash by leveraging access to an unattended workstation to read HTML source code within a victim's browser.

CVE-2014-3328

The Intercluster Sync Agent Service in Cisco Unified Presence Server allows remote attackers to cause a denial of service via a TCP SYN flood, aka Bug ID CSCun34125.

CVE-2014-3326

SQL injection vulnerability in the web framework in Cisco Security Manager 4.5 and 4.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCup26957.

CVE-2014-3324

Multiple cross-site scripting (XSS) vulnerabilities in the login page in the administrative web interface in Cisco TelePresence Server Software 4.0(2.8) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCup90060.

CVE-2014-3305

Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCuj81735.

CVE-2014-3301

The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading stack traces in returned messages, aka Bug ID CSCuj81700.

CVE-2014-3071

Cross-site scripting (XSS) vulnerability in the Data Quality Console in IBM InfoSphere Information Server 11.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL for adding a project connection.

CVE-2014-2966

The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended text restrictions via crafted characters, as demonstrated by bypassing an XSS protection mechanism.

This Alert covers CVE-2010-0896 for the mail component of the Sun Convergence product

This Sun Alert covers CVE-2010-0896 for the mail component of the Sun Convergence product.

14 april, 2010

This Alert Covers CVE-2010-0893 for the Mail Component of the Sun Convergence Product

This Alert covers CVE-2010-0893 for the mail component of the Sun Convergence product.

14 april, 2010

SunOS 5.10_x86: ucode driver patch

6905530 processor microcode code can panic when retrieving microcode revision.

02 february, 2010

[RHSA-2010:1003-01] Moderate: git security update

Red Hat Security Advisory - Moderate: git security update

21 december, 2010

[RHSA-2010:1002-01] Moderate: mod_auth_mysql security update

Red Hat Security Advisory - Moderate: mod_auth_mysql security update

21 december, 2010

[RHSA-2010:1000-01] Important: bind security update

Red Hat Security Advisory - Important: bind security update

20 december, 2010