CVE-2011-1585
published 2013-06-08CVE-2011-1585: The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not properly determine the associations between users and sessions…
PriorityP48low3.3CVSS 2.0
AVLACMAuNCPIPAN
EPSS
0.49%
39.6th percentile
The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not properly determine the associations between users and sessions, which allows local users to bypass CIFS share authentication by leveraging a mount of a share by a different user.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | < 2.6.36 | 2.6.36 |
| openstack | nova | >= 0 < 12.0.0a0 | 12.0.0a0 |
| suse | suse_linux_enterprise_server | — | — |
CVSS provenance
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat9.3CRITICAL
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux (OMAP4) vulnerabilities
vendor_ubuntu·2011-11-24·CVSS 3.3
CVE-2011-1585 [LOW] Linux (OMAP4) vulnerabilities
Title: Linux (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that CIFS incorrectly handled authentication. When a user
had a CIFS share mounted that required authentication, a local user could
mount the same share without knowing the correct password. (CVE-2011-1585)
Robert Swiecki discovered that mapping extensions were incorrectly handled.
A local attacker could exploit this to crash the system, leading to a
denial of service. (CVE-2011-2496)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules yo
Ubuntu
Linux (Maverick backport) vulnerabilities
vendor_ubuntu·2011-11-24·CVSS 3.3
CVE-2011-1585 [LOW] Linux (Maverick backport) vulnerabilities
Title: Linux (Maverick backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that CIFS incorrectly handled authentication. When a user
had a CIFS share mounted that required authentication, a local user could
mount the same share without knowing the correct password. (CVE-2011-1585)
Andrea Righi discovered a race condition in the KSM memory merging support.
If KSM was being used, a local attacker could exploit this to crash the
system, leading to a denial of service. (CVE-2011-2183)
Vasily Averin discovered that the NFS Lock Manager (NLM) incorrectly
handled unlock requests. A local attacker could exploit this to cause a
denial of service. (CVE-2011-2491)
Robert Swiecki discovered that mapping extensions were incorrectly handled.
A loca
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-11-21·CVSS 3.3
CVE-2011-1585 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that CIFS incorrectly handled authentication. When a user
had a CIFS share mounted that required authentication, a local user could
mount the same share without knowing the correct password. (CVE-2011-1585)
Andrea Righi discovered a race condition in the KSM memory merging support.
If KSM was being used, a local attacker could exploit this to crash the
system, leading to a denial of service. (CVE-2011-2183)
Vasily Averin discovered that the NFS Lock Manager (NLM) incorrectly
handled unlock requests. A local attacker could exploit this to cause a
denial of service. (CVE-2011-2491)
Robert Swiecki discovered that mapping extensions were incorrectly handled.
A local attacker co
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-11-21·CVSS 3.3
CVE-2011-1585 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that CIFS incorrectly handled authentication. When a user
had a CIFS share mounted that required authentication, a local user could
mount the same share without knowing the correct password. (CVE-2011-1585)
It was discovered that the GRE protocol incorrectly handled netns
initialization. A remote attacker could send a packet while the ip_gre
module was loading, and crash the system, leading to a denial of service.
(CVE-2011-1767)
It was discovered that the IP/IP protocol incorrectly handled netns
initialization. A remote attacker could send a packet while the ipip module
was loading, and crash the system, leading to a denial of service.
(CVE-2011-1768)
Vasily Averin discove
Ubuntu
Linux kernel (FSL-IMX51) vulnerabilities
vendor_ubuntu·2011-11-21·CVSS 3.3
CVE-2011-1585 [LOW] Linux kernel (FSL-IMX51) vulnerabilities
Title: Linux kernel (FSL-IMX51) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that CIFS incorrectly handled authentication. When a user
had a CIFS share mounted that required authentication, a local user could
mount the same share without knowing the correct password. (CVE-2011-1585)
It was discovered that the GRE protocol incorrectly handled netns
initialization. A remote attacker could send a packet while the ip_gre
module was loading, and crash the system, leading to a denial of service.
(CVE-2011-1767)
It was discovered that the IP/IP protocol incorrectly handled netns
initialization. A remote attacker could send a packet while the ipip module
was loading, and crash the system, leading to a denial of service.
(CVE-2011-1768)
Vasily Av
Ubuntu
Linux kernel (Natty backport) vulnerabilities
vendor_ubuntu·2011-11-09·CVSS 4.6
CVE-2011-1020 [MEDIUM] Linux kernel (Natty backport) vulnerabilities
Title: Linux kernel (Natty backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the /proc filesystem did not correctly handle
permission changes when programs executed. A local attacker could hold open
files to examine details about programs running with higher privileges,
potentially increasing the chances of exploiting additional
vulnerabilities. (CVE-2011-1020)
Vasiliy Kulikov discovered that the Bluetooth stack did not correctly clear
memory. A local attacker could exploit this to read kernel stack memory,
leading to a loss of privacy. (CVE-2011-1078)
Vasiliy Kulikov discovered that the Bluetooth stack did not correctly check
that device name strings were NULL terminated. A local attacker could
exploit this to crash the system,
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2011-09-29·CVSS 1.9
CVE-2010-4076 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Multiple kernel flaws have been fixed.
Dan Rosenberg discovered that multiple terminal ioctls did not correctly
initialize structure memory. A local attacker could exploit this to read
portions of kernel stack memory, leading to a loss of privacy.
(CVE-2010-4076, CVE-2010-4077)
Alex Shi and Eric Dumazet discovered that the network stack did not
correctly handle packet backlogs. A remote attacker could exploit this by
sending a large amount of network traffic to cause the system to run out of
memory, leading to a denial of service. (CVE-2010-4251, CVE-2010-4805)
It was discovered that the /proc filesystem did not correctly handle
permission changes when programs executed. A local attacker could hold open
files to examine details about program
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2011-09-26·CVSS 1.9
CVE-2010-4076 [LOW] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Multiple kernel flaws have been fixed.
Dan Rosenberg discovered that multiple terminal ioctls did not correctly
initialize structure memory. A local attacker could exploit this to read
portions of kernel stack memory, leading to a loss of privacy.
(CVE-2010-4076, CVE-2010-4077)
Alex Shi and Eric Dumazet discovered that the network stack did not
correctly handle packet backlogs. A remote attacker could exploit this by
sending a large amount of network traffic to cause the system to run out of
memory, leading to a denial of service. (CVE-2010-4251, CVE-2010-4805)
It was discovered that the /proc filesystem did not correctly handle
permission changes when programs executed. A local attacker could hold open
files to examine details about p
Ubuntu
Linux kernel (Marvel DOVE) vulnerabilities
vendor_ubuntu·2011-09-14·CVSS 1.9
CVE-2011-2213 [LOW] Linux kernel (Marvel DOVE) vulnerabilities
Title: Linux kernel (Marvel DOVE) vulnerabilities
Summary: Multiple kernel flaws have been fixed.
Dan Rosenberg discovered that multiple terminal ioctls did not correctly
initialize structure memory. A local attacker could exploit this to read
portions of kernel stack memory, leading to a loss of privacy.
(CVE-2010-4076, CVE-2010-4077)
Alex Shi and Eric Dumazet discovered that the network stack did not
correctly handle packet backlogs. A remote attacker could exploit this by
sending a large amount of network traffic to cause the system to run out of
memory, leading to a denial of service. (CVE-2010-4251, CVE-2010-4805)
It was discovered that the /proc filesystem did not correctly handle
permission changes when programs executed. A local attacker could hold open
files to examine details
Ubuntu
Linux kernel (Marvel DOVE) vulnerabilities
vendor_ubuntu·2011-09-13·CVSS 1.9
CVE-2011-2700 [LOW] Linux kernel (Marvel DOVE) vulnerabilities
Title: Linux kernel (Marvel DOVE) vulnerabilities
Summary: Multiple kernel flaws have been fixed.
Dan Rosenberg discovered that multiple terminal ioctls did not correctly
initialize structure memory. A local attacker could exploit this to read
portions of kernel stack memory, leading to a loss of privacy.
(CVE-2010-4076, CVE-2010-4077)
Alex Shi and Eric Dumazet discovered that the network stack did not
correctly handle packet backlogs. A remote attacker could exploit this by
sending a large amount of network traffic to cause the system to run out of
memory, leading to a denial of service. (CVE-2010-4251, CVE-2010-4805)
It was discovered that the /proc filesystem did not correctly handle
permission changes when programs executed. A local attacker could hold open
files to examine details
Red Hat
javascript: URLs in chrome documents (MFSA 2011-08)
vendor_redhat·2011-03-01·CVSS 9.3
CVE-2010-1585 [CRITICAL] javascript: URLs in chrome documents (MFSA 2011-08)
javascript: URLs in chrome documents (MFSA 2011-08)
The nsIScriptableUnescapeHTML.parseFragment method in the ParanoidFragmentSink protection mechanism in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 does not properly sanitize HTML in a chrome document, which makes it easier for remote attackers to execute arbitrary JavaScript with chrome privileges via a javascript: URI in input to an extension, as demonstrated by a javascript:alert sequence in (1) the HREF attribute of an A element or (2) the ACTION attribute of a FORM element.
Package: firefox (Red Hat Enterprise Linux Extended Update Support 4.8) - Affected
Package: firefox (Red Hat Enterprise Linux Extended Update Support 5.6) - Affected
Package: firefox (Red Hat Ente
Red Hat
kernel: cifs session reuse
vendor_redhat·2010-08-02·CVSS 3.3
CVE-2011-1585 [LOW] kernel: cifs session reuse
kernel: cifs session reuse
The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not properly determine the associations between users and sessions, which allows local users to bypass CIFS share authentication by leveraging a mount of a share by a different user.
Statement: This issue did not affect the versions of Linux kernel as shipped in Red Hat Enterprise Linux 4, 5, 6, and Red Hat Enterprise MRG as they did not ship mount.cifs with root setuid set. However, as a preventive meaasure, we have addressed this in Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1386.html and https://rhn.redhat.com/errata/RHSA-2011-1253.html. Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycl
GHSA
OpenStack Nova Long server names grow nova-api log files significantly
ghsa·2022-05-14
CVE-2012-1585 [MEDIUM] OpenStack Nova Long server names grow nova-api log files significantly
OpenStack Nova Long server names grow nova-api log files significantly
OpenStack Compute (Nova) Essex before 2011.3 allows remote authenticated users to cause a denial of service (Nova-API log file and disk consumption) via a long server name.
GHSA
GHSA-x654-xc6m-hm65: The cifs_find_smb_ses function in fs/cifs/connect
ghsa_unreviewed·2022-05-13
CVE-2011-1585 [LOW] GHSA-x654-xc6m-hm65: The cifs_find_smb_ses function in fs/cifs/connect
The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not properly determine the associations between users and sessions, which allows local users to bypass CIFS share authentication by leveraging a mount of a share by a different user.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1585 openstack-nova: Long server names grow nova-api log files significantly [fedora-16]
bugzilla·2012-03-29·CVSS 4.0
CVE-2012-1585 [MEDIUM] CVE-2012-1585 openstack-nova: Long server names grow nova-api log files significantly [fedora-16]
CVE-2012-1585 openstack-nova: Long server names grow nova-api log files significantly [fedora-16]
please see the bug #808146 for more details on this vulnerability
Discussion:
openstack-nova-2011.3.1-7.fc16 has been submitted as an update for Fedora 16.
https://admin.fedoraproject.org/updates/openstack-nova-2011.3.1-7.fc16
---
Package openstack-nova-2011.3.1-7.fc16:
* should fix your issue,
* was pushed to the Fedora 16 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing openstack-nova-2011.3.1-7.fc16'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2012-5026/openstack-nova-2011.3.1-7.fc16
then log in and leave karma (feedback).
---
Bugzilla
CVE-2012-1585 openstack-nova: Long server names grow nova-api log files significantly [epel-6]
bugzilla·2012-03-29·CVSS 4.0
CVE-2012-1585 [MEDIUM] CVE-2012-1585 openstack-nova: Long server names grow nova-api log files significantly [epel-6]
CVE-2012-1585 openstack-nova: Long server names grow nova-api log files significantly [epel-6]
please see the bug #808146 for more details on this vulnerability
Discussion:
openstack-nova-2011.3.1-7.el6 has been submitted as an update for Fedora EPEL 6.
https://admin.fedoraproject.org/updates/openstack-nova-2011.3.1-7.el6
---
openstack-nova-2011.3.1-8.el6 has been submitted as an update for Fedora EPEL 6.
https://admin.fedoraproject.org/updates/openstack-nova-2011.3.1-8.el6
---
Package openstack-nova-2011.3.1-8.el6:
* should fix your issue,
* was pushed to the Fedora EPEL 6 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=epel-testing openstack-nova-2011.3.1-8.el6'
as soon as you are able to.
Please go t
Bugzilla
CVE-2011-1585 kernel: cifs session reuse
bugzilla·2011-04-18·CVSS 3.3
CVE-2011-1585 [LOW] CVE-2011-1585 kernel: cifs session reuse
CVE-2011-1585 kernel: cifs session reuse
When one user has mounted a cifs share that requires authentication, another user could mount the same share without knowing the correct password.
A way to exploit this would be through mount.cifs if it's installed setuid root.
On Red Hat Enterprise Linux, mount.cifs is not root setuid by default.
Upstream commits:
http://git.kernel.org/linus/4ff67b720c02c36e54d55b88c2931879b7db1cd2
http://git.kernel.org/linus/fc87a40677bbe0937e2ff0642c7e83c9a4813f3d
http://git.kernel.org/linus/24e6cf92fde1f140d8eb0bf7cd24c2c78149b6b2
Discussion:
Statement:
This issue did not affect the versions of Linux kernel as shipped in Red Hat Enterprise Linux 4, 5, 6, and Red Hat Enterprise MRG as they did not ship mount.cifs with root setuid set. However, as a prevent
Bugzilla
CVE-2010-1585 Mozilla ParanoidFragmentSink allows javascript: URLs in chrome documents (MFSA 2011-08)
bugzilla·2011-02-04·CVSS 9.3
CVE-2010-1585 [CRITICAL] CVE-2010-1585 Mozilla ParanoidFragmentSink allows javascript: URLs in chrome documents (MFSA 2011-08)
CVE-2010-1585 Mozilla ParanoidFragmentSink allows javascript: URLs in chrome documents (MFSA 2011-08)
Mozilla security developer Roberto Suggi Liverani reported
that ParanoidFragmentSink, a class used to sanitize potentially
unsafe HTML for display, allows javascript: URLs and other
inline JavaScript when the embedding document is a chrome document.
While there are no unsafe uses of this class in any released products,
extension code could have potentially used it in an unsafe manner.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2011/mfsa2011-08.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0311 https://rhn.redhat.com/errata/RHSA-2011-0311.html
---
This issue has been addressed in following prod
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4ff67b720c02c36e54d55b88c2931879b7db1cd2http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://www.openwall.com/lists/oss-security/2011/04/15/8https://bugzilla.redhat.com/show_bug.cgi?id=697394https://github.com/torvalds/linux/commit/4ff67b720c02c36e54d55b88c2931879b7db1cd2http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4ff67b720c02c36e54d55b88c2931879b7db1cd2http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://www.openwall.com/lists/oss-security/2011/04/15/8https://bugzilla.redhat.com/show_bug.cgi?id=697394https://github.com/torvalds/linux/commit/4ff67b720c02c36e54d55b88c2931879b7db1cd2
2013-06-08
Published