CVE-2010-2492
published 2010-09-08CVE-2010-2492: Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users…
PriorityP433high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.43%
35.0th percentile
Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash) via unspecified vectors.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| avaya | aura_communication_manager | — | — |
| avaya | aura_presence_services | — | — |
| avaya | aura_presence_services | — | — |
| avaya | aura_presence_services | — | — |
| avaya | aura_session_manager | — | — |
| avaya | aura_session_manager | — | — |
| avaya | aura_session_manager | — | — |
| avaya | aura_system_manager | — | — |
| avaya | aura_system_manager | — | — |
| avaya | aura_system_manager | — | — |
| avaya | aura_system_manager | — | — |
| avaya | aura_system_platform | — | — |
| avaya | aura_system_platform | — | — |
| avaya | aura_voice_portal | — | — |
| avaya | aura_voice_portal | — | — |
| avaya | iq | — | — |
| avaya | iq | — | — |
| linux | linux_kernel | < 2.6.35 | 2.6.35 |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_workstation | — | — |
| vmware | vsphere | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat7.8HIGH
vendor_ubuntu1.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESX third party updates for Service Console packages glibc and dhcp
vendor_vmware·2011-10-12·CVSS 4.7
CVE-2010-0296 [MEDIUM] VMware ESX third party updates for Service Console packages glibc and dhcp
VMSA-2011-0012: VMware ESX third party updates for Service Console packages glibc and dhcp
a. ESX third party update for Service Console kernel This update takes the console OS kernel package to kernel-2.6.18-238.9.1 which resolves multiple security issues. The Common Vulnerabilities and Exposures project ( cve.mitre.org) has assigned the names CVE-2010-1083, CVE-2010-2492, CVE-2010-2798, CVE-2010-2938, CVE-2010-2942, CVE-2010-2943, CVE-2010-3015, CVE-2010-3066, CVE-2010-3067, CVE-2010-3078, CVE-2010-3086, CVE-2010-3296, CVE-2010-3432, CVE-2010-3442, CVE-2010-3477, CVE-2010-3699, CVE-2010-3858, CVE-2010-3859, CVE-2010-3865, CVE-2010-3876, CVE-2010-3877, CVE-2010-3880, CVE-2010-3904, CVE-2010-4072, CVE-2010-4073, CVE-2010-4075, CVE-2010-4080, CVE-2010-4081, CVE-2010-4083, CVE-2010-4157, CV
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2010-08-04·CVSS 1.2
CVE-2008-7256 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Multiple security flaws.
Junjiro R. Okajima discovered that knfsd did not correctly handle
strict overcommit. A local attacker could exploit this to crash knfsd,
leading to a denial of service. (Only Ubuntu 6.06 LTS and 8.04 LTS were
affected.) (CVE-2008-7256, CVE-2010-1643)
Chris Guo, Jukka Taimisto, and Olli Jarva discovered that SCTP did
not correctly handle invalid parameters. A remote attacker could send
specially crafted traffic that could crash the system, leading to a
denial of service. (CVE-2010-1173)
Mario Mikocevic discovered that GFS2 did not correctly handle certain
quota structures. A local attacker could exploit this to crash the
system, leading to a denial of service. (Ubuntu 6.06 LTS was not
affected.) (CVE-2010-1436)
Toshi
Red Hat
kernel: ecryptfs_uid_hash() buffer overflow
vendor_redhat·2010-07-13·CVSS 7.8
CVE-2010-2492 [HIGH] CWE-228 kernel: ecryptfs_uid_hash() buffer overflow
kernel: ecryptfs_uid_hash() buffer overflow
Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash) via unspecified vectors.
Statement: The Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, and Red Hat
Enterprise MRG did not include support for eCryptfs, and therefore are not
affected by this issue. A future update in Red Hat Enterprise Linux 6 may
address this flaw. This was addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2010-0723.html.
GHSA
GHSA-gqmg-rx5r-xhwg: Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging
ghsa_unreviewed·2022-05-13
CVE-2010-2492 [HIGH] CWE-120 GHSA-gqmg-rx5r-xhwg: Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging
Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash) via unspecified vectors.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a6f80fb7b5986fda663d94079d3bba0937a6b6ffhttp://secunia.com/advisories/42890http://secunia.com/advisories/46397http://support.avaya.com/css/P8/documents/100113326http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.35http://www.mandriva.com/security/advisories?name=MDVSA-2010:172http://www.mandriva.com/security/advisories?name=MDVSA-2010:198http://www.redhat.com/support/errata/RHSA-2010-0723.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0007.htmlhttp://www.securityfocus.com/archive/1/520102/100/0/threadedhttp://www.vmware.com/security/advisories/VMSA-2011-0012.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=611385http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a6f80fb7b5986fda663d94079d3bba0937a6b6ffhttp://secunia.com/advisories/42890http://secunia.com/advisories/46397http://support.avaya.com/css/P8/documents/100113326http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.35http://www.mandriva.com/security/advisories?name=MDVSA-2010:172http://www.mandriva.com/security/advisories?name=MDVSA-2010:198http://www.redhat.com/support/errata/RHSA-2010-0723.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0007.htmlhttp://www.securityfocus.com/archive/1/520102/100/0/threadedhttp://www.vmware.com/security/advisories/VMSA-2011-0012.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=611385
2010-09-08
Published