CVE-2010-0727
published 2010-03-16CVE-2010-0727: The gfs2_lock function in the Linux kernel before 2.6.34-rc1-next-20100312, and the gfs_lock function in the Linux kernel on Red Hat Enterprise Linux (RHEL) 5…
PriorityP415medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.58%
43.9th percentile
The gfs2_lock function in the Linux kernel before 2.6.34-rc1-next-20100312, and the gfs_lock function in the Linux kernel on Red Hat Enterprise Linux (RHEL) 5 and 6, does not properly remove POSIX locks on files that are setgid without group-execute permission, which allows local users to cause a denial of service (BUG and system crash) by locking a file on a (1) GFS or (2) GFS2 filesystem, and then changing this file's permissions.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| linux | linux_kernel | <= 2.6.33.1 | — |
| linux | linux_kernel | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
vendor_redhat4.9MEDIUM
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel regression
vendor_ubuntu·2010-06-04·CVSS 4.7
CVE-2010-0419 [MEDIUM] Linux kernel regression
Title: Linux kernel regression
Summary: KVM regressed under some conditions in the Linux kernel.
USN-947-1 fixed vulnerabilities in the Linux kernel. Fixes for
CVE-2010-0419 caused failures when using KVM in certain situations.
This update reverts that fix until a better solution can be found.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the Linux kernel did not correctly handle memory
protection of the Virtual Dynamic Shared Object page when running
a 32-bit application on a 64-bit kernel. A local attacker could
exploit this to cause a denial of service. (Only affected Ubuntu 6.06
LTS.) (CVE-2009-4271)
It was discovered that the r8169 network driver did not correctly check
the size of Ethernet frames. A remote attacker could send specially
cr
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2010-06-03·CVSS 4.7
CVE-2009-4271 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Multiple flaws in the Linux kernel.
It was discovered that the Linux kernel did not correctly handle memory
protection of the Virtual Dynamic Shared Object page when running
a 32-bit application on a 64-bit kernel. A local attacker could
exploit this to cause a denial of service. (Only affected Ubuntu 6.06
LTS.) (CVE-2009-4271)
It was discovered that the r8169 network driver did not correctly check
the size of Ethernet frames. A remote attacker could send specially
crafted traffic to crash the system, leading to a denial of service.
(CVE-2009-4537)
Wei Yongjun discovered that SCTP did not correctly validate certain
chunks. A remote attacker could send specially crafted traffic to
monopolize CPU resources, leading to a denial of service. (Onl
Red Hat
kernel: bug in GFS/GFS2 locking code leads to dos
vendor_redhat·2010-03-11·CVSS 4.9
CVE-2010-0727 [MEDIUM] kernel: bug in GFS/GFS2 locking code leads to dos
kernel: bug in GFS/GFS2 locking code leads to dos
The gfs2_lock function in the Linux kernel before 2.6.34-rc1-next-20100312, and the gfs_lock function in the Linux kernel on Red Hat Enterprise Linux (RHEL) 5 and 6, does not properly remove POSIX locks on files that are setgid without group-execute permission, which allows local users to cause a denial of service (BUG and system crash) by locking a file on a (1) GFS or (2) GFS2 filesystem, and then changing this file's permissions.
Statement: This issue did not affect the version of Linux kernel as shipped with Red Hat Enterprise MRG, as it did not include support for the GFS and GFS2 file systems.
For the GFS issue, it was addressed in Red Hat Enterprise Linux 3 in the gfs package, 4 in the GFS-kernel package, and 5 in the gfs-kmod pack
GHSA
GHSA-xfgm-rcpf-gf3q: The gfs2_lock function in the Linux kernel before 2
ghsa_unreviewed·2022-05-02
CVE-2010-0727 [MEDIUM] GHSA-xfgm-rcpf-gf3q: The gfs2_lock function in the Linux kernel before 2
The gfs2_lock function in the Linux kernel before 2.6.34-rc1-next-20100312, and the gfs_lock function in the Linux kernel on Red Hat Enterprise Linux (RHEL) 5 and 6, does not properly remove POSIX locks on files that are setgid without group-execute permission, which allows local users to cause a denial of service (BUG and system crash) by locking a file on a (1) GFS or (2) GFS2 filesystem, and then changing this file's permissions.
GHSA
GHSA-f625-g7x4-5whm: The nfs_lock function in fs/nfs/file
ghsa_unreviewed·2022-05-01·CVSS 4.9
CVE-2007-6733 [MEDIUM] GHSA-f625-g7x4-5whm: The nfs_lock function in fs/nfs/file
The nfs_lock function in fs/nfs/file.c in the Linux kernel 2.6.9 does not properly remove POSIX locks on files that are setgid without group-execute permission, which allows local users to cause a denial of service (BUG and system crash) by locking a file on an NFS filesystem and then changing this file's permissions, a related issue to CVE-2010-0727.
No detection rules found.
Exploit-DB
Oracle 9i XDB (Windows x86) - FTP UNLOCK Overflow (Metasploit)
exploitdb·2010-10-05
CVE-2003-0727 Oracle 9i XDB (Windows x86) - FTP UNLOCK Overflow (Metasploit)
Oracle 9i XDB (Windows x86) - FTP UNLOCK Overflow (Metasploit)
---
##
# $Id: oracle9i_xdb_ftp_unlock.rb 10559 2010-10-05 23:41:17Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Oracle 9i XDB FTP UNLOCK Overflow (win32)',
'Description' => %q{
By passing an overly long token to the UNLOCK command, a
stack based buffer overflow occurs. David Litchfield, has
illustrated multiple vulnerabilities in the Oracle 9i XML
Database (XDB), during a seminar on "Variations in exploit
methods between Linux and Windows" presented at the Blackhat
c
Exploit-DB
Oracle 9i XDB (Windows x86) - HTTP PASS Overflow (Metasploit)
exploitdb·2010-09-20
CVE-2003-0727 Oracle 9i XDB (Windows x86) - HTTP PASS Overflow (Metasploit)
Oracle 9i XDB (Windows x86) - HTTP PASS Overflow (Metasploit)
---
##
# $Id: oracle9i_xdb_pass.rb 10394 2010-09-20 08:06:27Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Oracle 9i XDB HTTP PASS Overflow (win32)',
'Description' => %q{
This module exploits a stack buffer overflow in the authorization
code of the Oracle 9i HTTP XDB service. David Litchfield,
has illustrated multiple vulnerabilities in the Oracle
9i XML Database (XDB), during a seminar on "Variations
in exploit methods between Linux and Windows" presented
at the Black
Exploit-DB
Oracle 9i XDB (Windows x86) - FTP PASS Overflow (Metasploit)
exploitdb·2010-04-30
CVE-2003-0727 Oracle 9i XDB (Windows x86) - FTP PASS Overflow (Metasploit)
Oracle 9i XDB (Windows x86) - FTP PASS Overflow (Metasploit)
---
##
# $Id: oracle9i_xdb_ftp_pass.rb 9179 2010-04-30 08:40:19Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Oracle 9i XDB FTP PASS Overflow (win32)',
'Description' => %q{
By passing an overly long string to the PASS command, a
stack based buffer overflow occurs. David Litchfield, has
illustrated multiple vulnerabilities in the Oracle 9i XML
Database (XDB), during a seminar on "Variations in exploit
methods between Linux and Windows" presented at the Blackhat
conferenc
http://lkml.org/lkml/2010/3/11/269http://secunia.com/advisories/39830http://securitytracker.com/id?1023809http://www.debian.org/security/2010/dsa-2053http://www.kernel.org/pub/linux/kernel/v2.6/next/patch-v2.6.34-rc1-next-20100312.bz2http://www.mandriva.com/security/advisories?name=MDVSA-2010:066http://www.openwall.com/lists/oss-security/2010/03/12/1http://www.redhat.com/support/errata/RHSA-2010-0330.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0380.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0521.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=570863https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11392http://lkml.org/lkml/2010/3/11/269http://secunia.com/advisories/39830http://securitytracker.com/id?1023809http://www.debian.org/security/2010/dsa-2053http://www.kernel.org/pub/linux/kernel/v2.6/next/patch-v2.6.34-rc1-next-20100312.bz2http://www.mandriva.com/security/advisories?name=MDVSA-2010:066http://www.openwall.com/lists/oss-security/2010/03/12/1http://www.redhat.com/support/errata/RHSA-2010-0330.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0380.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0521.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=570863https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11392
2010-03-16
Published