CVE-2009-4020
published 2009-12-04CVE-2009-4020: Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical…
PriorityP341high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
4.95%
91.2th percentile
Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical File System (HFS) filesystem, related to the hfs_readdir function in fs/hfs/dir.c.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.17-1 (bookworm) | linux 3.2.17-1 (bookworm) |
| linux | linux_kernel | <= 3.3.3 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.2.17-1 | 3.2.17-1 |
| linux | linux_kernel | >= 0 < 3.2.17-1 | 3.2.17-1 |
| linux | linux_kernel | >= 0 < 3.2.17-1 | 3.2.17-1 |
| linux | linux_kernel | >= 0 < 3.2.17-1 | 3.2.17-1 |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9w77-vr2w-558v: Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3
ghsa_unreviewed·2022-05-17·CVSS 7.8
CVE-2012-2319 [HIGH] GHSA-9w77-vr2w-558v: Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3
Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3.3.5 allow local users to gain privileges via a crafted HFS plus filesystem, a related issue to CVE-2009-4020.
GHSA
GHSA-qwp9-6w2r-7cq2: Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2
ghsa_unreviewed·2022-05-02
CVE-2009-4020 [HIGH] CWE-119 GHSA-qwp9-6w2r-7cq2: Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2
Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical File System (HFS) filesystem, related to the hfs_readdir function in fs/hfs/dir.c.
OSV
CVE-2012-2319: Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3
osv·2012-05-17·CVSS 7.8
CVE-2012-2319 [HIGH] CVE-2012-2319: Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3
Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3.3.5 allow local users to gain privileges via a crafted HFS plus filesystem, a related issue to CVE-2009-4020.
Red Hat
kernel: Buffer overflow in the HFS plus filesystem (different issue than CVE-2009-4020)
vendor_redhat·2012-05-04·CVSS 7.8
CVE-2012-2319 [HIGH] CWE-119 kernel: Buffer overflow in the HFS plus filesystem (different issue than CVE-2009-4020)
kernel: Buffer overflow in the HFS plus filesystem (different issue than CVE-2009-4020)
Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3.3.5 allow local users to gain privileges via a crafted HFS plus filesystem, a related issue to CVE-2009-4020.
Statement: This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG, as those versions do not have CONFIG_HFSPLUS_FS option enabled.
The Red Hat Security Response Team has rated this issue as having low security impact. A future kernel updates in Red Hat Enterprise Linux 5 may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
P
Debian
CVE-2012-2319: linux - Multiple buffer overflows in the hfsplus filesystem implementation in the Linux ...
vendor_debian·2012·CVSS 7.8
CVE-2012-2319 [HIGH] CVE-2012-2319: linux - Multiple buffer overflows in the hfsplus filesystem implementation in the Linux ...
Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3.3.5 allow local users to gain privileges via a crafted HFS plus filesystem, a related issue to CVE-2009-4020.
Scope: local
bookworm: resolved (fixed in 3.2.17-1)
bullseye: resolved (fixed in 3.2.17-1)
forky: resolved (fixed in 3.2.17-1)
sid: resolved (fixed in 3.2.17-1)
trixie: resolved (fixed in 3.2.17-1)
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2010-02-05·CVSS 7.8
CVE-2009-4031 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
Amerigo Wang and Eric Sesterhenn discovered that the HFS and ext4
filesystems did not correctly check certain disk structures. If a user
were tricked into mounting a specially crafted filesystem, a remote
attacker could crash the system or gain root privileges. (CVE-2009-4020,
CVE-2009-4308)
It was discovered that FUSE did not correctly check certain requests.
A local attacker with access to FUSE mounts could exploit this to
crash the system or possibly gain root privileges. Ubuntu 9.10 was not
affected. (CVE-2009-4021)
It was discovered that KVM did not correctly decode certain guest
instructions. A local attacker in a guest could exploit this to
trigger high scheduling latency in the host, leading to a denial o
Red Hat
kernel: hfs buffer overflow
vendor_redhat·2009-12-04·CVSS 7.8
CVE-2009-4020 [HIGH] CWE-119 kernel: hfs buffer overflow
kernel: hfs buffer overflow
Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical File System (HFS) filesystem, related to the hfs_readdir function in fs/hfs/dir.c.
Statement: This issue did not affect the version of the Linux kernel as shipped with Red Hat Enterprise MRG as the affected driver is not enabled in this kernel.
Red Hat Enterprise Linux 3 is now in Production 3 of the maintenance life-cycle, https://access.redhat.com/support/policy/updates/errata, and this issue is rated as having low impact, therefore the fix for this issue is not currently planned to be included in the future updates.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2319 kernel: Buffer overflow in the HFS plus filesystem (different issue than CVE-2009-4020) [fedora-all]
bugzilla·2012-05-09·CVSS 7.8
CVE-2012-2319 [HIGH] CVE-2012-2319 kernel: Buffer overflow in the HFS plus filesystem (different issue than CVE-2009-4020) [fedora-all]
CVE-2012-2319 kernel: Buffer overflow in the HFS plus filesystem (different issue than CVE-2009-4020) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedora
Bugzilla
CVE-2012-2319 kernel: Buffer overflow in the HFS plus filesystem (different issue than CVE-2009-4020)
bugzilla·2012-05-07·CVSS 7.8
CVE-2012-2319 [HIGH] CVE-2012-2319 kernel: Buffer overflow in the HFS plus filesystem (different issue than CVE-2009-4020)
CVE-2012-2319 kernel: Buffer overflow in the HFS plus filesystem (different issue than CVE-2009-4020)
Previously Common Vulnerabilities and Exposures assigned an identifier of CVE-2009-4020 to the following vulnerability:
Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical File System (HFS) filesystem, related to the hfs_readdir function in fs/hfs/dir.c.
Recently:
[1] http://www.openwall.com/lists/oss-security/2012/05/07/3
Timo Warns pointed out similar flaws exists in the HFS plus file system.
Relevant upstream patch:
[2] http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=6f24f892871acc47b40dd594c63606a17c714f77
Discussion:
The CVE identifier of CVE-
Bugzilla
CVE-2009-4020 kernel: hfs buffer overflow
bugzilla·2009-11-24·CVSS 7.8
CVE-2009-4020 [HIGH] CVE-2009-4020 kernel: hfs buffer overflow
CVE-2009-4020 kernel: hfs buffer overflow
Description of problem:
A specially-crafted Hierarchical File System (HFS) filesystem could cause a buffer overflow to occur in a process's kernel stack during a memcpy() call within the hfs_bnode_read() function (at fs/hfs/bnode.c:24). The attacker can provide the source buffer and length, and the destination buffer is a local variable of a fixed length. This local variable (passed as "&entry" from fs/hfs/dir.c:112 and allocated on line 60) is stored in the stack frame of hfs_bnode_read()'s caller, which is hfs_readdir(). Because the hfs_readdir() function executes upon any attempt to read a directory on the filesystem, it gets called whenever a user attempts to inspect any filesystem contents.
Discussion:
Created attachment 373294
patch for rh
http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00007.htmlhttp://marc.info/?l=linux-mm-commits&m=125987755823047&w=2http://secunia.com/advisories/38276http://secunia.com/advisories/39742http://support.avaya.com/css/P8/documents/100073666http://userweb.kernel.org/~akpm/mmotm/broken-out/hfs-fix-a-potential-buffer-overflow.patchhttp://www.debian.org/security/2010/dsa-2005http://www.novell.com/linux/security/advisories/2010_23_kernel.htmlhttp://www.openwall.com/lists/oss-security/2009/12/04/1https://bugzilla.redhat.com/show_bug.cgi?id=540736https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10091https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6750https://rhn.redhat.com/errata/RHSA-2010-0046.htmlhttps://rhn.redhat.com/errata/RHSA-2010-0095.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00007.htmlhttp://marc.info/?l=linux-mm-commits&m=125987755823047&w=2http://secunia.com/advisories/38276http://secunia.com/advisories/39742http://support.avaya.com/css/P8/documents/100073666http://userweb.kernel.org/~akpm/mmotm/broken-out/hfs-fix-a-potential-buffer-overflow.patchhttp://www.debian.org/security/2010/dsa-2005http://www.novell.com/linux/security/advisories/2010_23_kernel.htmlhttp://www.openwall.com/lists/oss-security/2009/12/04/1https://bugzilla.redhat.com/show_bug.cgi?id=540736https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10091https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6750https://rhn.redhat.com/errata/RHSA-2010-0046.htmlhttps://rhn.redhat.com/errata/RHSA-2010-0095.html
2009-12-04
Published