CVE-2009-1633
published 2009-05-28CVE-2009-1633: Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption)…
PriorityP427high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
3.03%
86.2th percentile
Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malformed Unicode string, related to Unicode string area alignment in fs/cifs/sess.c; or (2) long Unicode characters, related to fs/cifs/cifssmb.c and the cifs_readdir function in fs/cifs/readdir.c.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| linux | linux_kernel | < 2.6.29.4 | 2.6.29.4 |
| vmware | esxi | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_redhat7.1HIGH
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r7qx-6x2x-phmm: Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2
ghsa_unreviewed·2022-05-02
CVE-2009-1633 [HIGH] CWE-119 GHSA-r7qx-6x2x-phmm: Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2
Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malformed Unicode string, related to Unicode string area alignment in fs/cifs/sess.c; or (2) long Unicode characters, related to fs/cifs/cifssmb.c and the cifs_readdir function in fs/cifs/readdir.c.
VMware
VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
vendor_vmware·2009-11-20·CVSS 5.0
CVE-2007-2052 [MEDIUM] VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
VMSA-2009-0016: VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
a. JRE Security Update JRE update to version 1.5.0_20, which addresses multiple security issues that existed in earlier releases of JRE. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_18: CVE-2009-1093, CVE-2009-1094, CVE-2009-1095, CVE-2009-1096, CVE-2009-1097, CVE-2009-1098, CVE-2009-1099, CVE-2009-1100, CVE-2009-1101, CVE-2009-1102, CVE-2009-1103, CVE-2009-1104, CVE-2009-1105, CVE-2009-1106, and CVE-2009-1107. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_20: CVE-2009-
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2009-07-02·CVSS 4.9
CVE-2009-1242 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
Igor Zhbanov discovered that NFS clients were able to create device nodes
even when root_squash was enabled. An authenticated remote attacker
could create device nodes with open permissions, leading to a loss of
privacy or escalation of privileges. Only Ubuntu 8.10 and 9.04 were
affected. (CVE-2009-1072)
Dan Carpenter discovered that SELinux did not correctly handle
certain network checks when running with compat_net=1. A local
attacker could exploit this to bypass network checks. Default Ubuntu
installations do not enable SELinux, and only Ubuntu 8.10 and 9.04 were
affected. (CVE-2009-1184)
Shaohua Li discovered that memory was not correctly initialized in the
AGP subsystem. A local attacker could potentially re
Red Hat
kernel: cifs: fix potential buffer overruns when converting unicode strings sent by server
vendor_redhat·2009-04-14·CVSS 7.1
CVE-2009-1633 [HIGH] CWE-228 kernel: cifs: fix potential buffer overruns when converting unicode strings sent by server
kernel: cifs: fix potential buffer overruns when converting unicode strings sent by server
Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malformed Unicode string, related to Unicode string area alignment in fs/cifs/sess.c; or (2) long Unicode characters, related to fs/cifs/cifssmb.c and the cifs_readdir function in fs/cifs/readdir.c.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, and 3.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/sfrench/cifs-2.6.git%3Ba=commit%3Bh=7b0c8fcff47a885743125dd843db64af41af5a61http://git.kernel.org/?p=linux/kernel/git/sfrench/cifs-2.6.git%3Ba=commit%3Bh=968460ebd8006d55661dec0fb86712b40d71c413http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=27b87fe52baba0a55e9723030e76fce94fabcea4http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.htmlhttp://marc.info/?l=oss-security&m=124099284225229&w=2http://marc.info/?l=oss-security&m=124099371726547&w=2http://secunia.com/advisories/35217http://secunia.com/advisories/35226http://secunia.com/advisories/35298http://secunia.com/advisories/35656http://secunia.com/advisories/35847http://secunia.com/advisories/36051http://secunia.com/advisories/36327http://secunia.com/advisories/37351http://secunia.com/advisories/37471http://wiki.rpath.com/Advisories:rPSA-2009-0111http://www.debian.org/security/2009/dsa-1809http://www.debian.org/security/2009/dsa-1844http://www.debian.org/security/2009/dsa-1865http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.29.4http://www.mandriva.com/security/advisories?name=MDVSA-2009:148http://www.openwall.com/lists/oss-security/2009/05/14/1http://www.openwall.com/lists/oss-security/2009/05/14/4http://www.openwall.com/lists/oss-security/2009/05/15/2http://www.redhat.com/support/errata/RHSA-2009-1157.htmlhttp://www.securityfocus.com/archive/1/505254/100/0/threadedhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/bid/34612http://www.ubuntu.com/usn/usn-793-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/3316https://bugzilla.redhat.com/show_bug.cgi?id=496572https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8588https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9525https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01126.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-May/msg01271.htmlhttp://git.kernel.org/?p=linux/kernel/git/sfrench/cifs-2.6.git%3Ba=commit%3Bh=7b0c8fcff47a885743125dd843db64af41af5a61http://git.kernel.org/?p=linux/kernel/git/sfrench/cifs-2.6.git%3Ba=commit%3Bh=968460ebd8006d55661dec0fb86712b40d71c413http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=27b87fe52baba0a55e9723030e76fce94fabcea4http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.htmlhttp://marc.info/?l=oss-security&m=124099284225229&w=2http://marc.info/?l=oss-security&m=124099371726547&w=2http://secunia.com/advisories/35217http://secunia.com/advisories/35226http://secunia.com/advisories/35298http://secunia.com/advisories/35656http://secunia.com/advisories/35847http://secunia.com/advisories/36051http://secunia.com/advisories/36327http://secunia.com/advisories/37351http://secunia.com/advisories/37471http://wiki.rpath.com/Advisories:rPSA-2009-0111http://www.debian.org/security/2009/dsa-1809http://www.debian.org/security/2009/dsa-1844http://www.debian.org/security/2009/dsa-1865http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.29.4http://www.mandriva.com/security/advisories?name=MDVSA-2009:148http://www.openwall.com/lists/oss-security/2009/05/14/1http://www.openwall.com/lists/oss-security/2009/05/14/4http://www.openwall.com/lists/oss-security/2009/05/15/2http://www.redhat.com/support/errata/RHSA-2009-1157.htmlhttp://www.securityfocus.com/archive/1/505254/100/0/threadedhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/bid/34612http://www.ubuntu.com/usn/usn-793-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/3316https://bugzilla.redhat.com/show_bug.cgi?id=496572https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8588https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9525https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01126.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-May/msg01271.html
2009-05-28
Published