CVE-2011-3630
published 2019-11-26CVE-2011-3630: Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A…
PriorityP350high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.66%
84.0th percentile
Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory tree, and trick the local user into consolidating it, leading to hardlink executable crash, or, potentially arbitrary code execution with the privileges of the user running the hardlink executable.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | hardlink | — | — |
| hardlink | hardlink | — | — |
| hardlink_project | hardlink | < 0.1.2 | 0.1.2 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_debian8.8LOW
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
hardlink: Multiple stack-based buffer overflows when run on a tree with deeply nested directories
vendor_redhat·2011-10-15·CVSS 8.8
CVE-2011-3630 [HIGH] CWE-121 hardlink: Multiple stack-based buffer overflows when run on a tree with deeply nested directories
hardlink: Multiple stack-based buffer overflows when run on a tree with deeply nested directories
Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory tree, and trick the local user into consolidating it, leading to hardlink executable crash, or, potentially arbitrary code execution with the privileges of the user running the hardlink executable.
Statement: This issue does not affect the version of hardlink, as shipped with Red Hat Enterprise Linux 5 and 6.
Package: hardlink (Red Hat Enterprise Linux 5) - Not affected
Package: hardlink (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2011-3630: hardlink - Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws bec...
vendor_debian·2011·CVSS 8.8
CVE-2011-3630 [HIGH] CVE-2011-3630: hardlink - Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws bec...
Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory tree, and trick the local user into consolidating it, leading to hardlink executable crash, or, potentially arbitrary code execution with the privileges of the user running the hardlink executable.
Scope: local
bullseye: resolved
GHSA
GHSA-pc7f-j836-p34f: Hardlink before 0
ghsa_unreviewed·2022-04-22
CVE-2011-3630 [HIGH] CWE-787 GHSA-pc7f-j836-p34f: Hardlink before 0
Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory tree, and trick the local user into consolidating it, leading to hardlink executable crash, or, potentially arbitrary code execution with the privileges of the user running the hardlink executable.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3630 CVE-2011-3631 CVE-2011-3632 hardlink various flaws [fedora-all]
bugzilla·2011-10-17·CVSS 8.8
CVE-2011-3630 [HIGH] CVE-2011-3630 CVE-2011-3631 CVE-2011-3632 hardlink various flaws [fedora-all]
CVE-2011-3630 CVE-2011-3631 CVE-2011-3632 hardlink various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=746709
Please note: this issue affects multi
Bugzilla
CVE-2011-3630 hardlink: Multiple stack-based buffer overflows when run on a tree with deeply nested directories
bugzilla·2011-10-17·CVSS 8.8
CVE-2011-3630 [HIGH] CVE-2011-3630 hardlink: Multiple stack-based buffer overflows when run on a tree with deeply nested directories
CVE-2011-3630 hardlink: Multiple stack-based buffer overflows when run on a tree with deeply nested directories
Multiple stack-based buffer overflow flaws were found in the way hardlink, the tool for consolidation of duplicate files via hardlinks, processed directory trees with deeply nested directories. A remote attacker could provide a specially-crafted directory tree, and trick the local user into consolidating it, leading to hardlink executable crash, or, potentially arbitrary code execution with the privileges of the user running the hardlink executable.
References:
[1] http://www.openwall.com/lists/oss-security/2011/10/15/2
[2] https://bugs.gentoo.org/show_bug.cgi?id=387269
[3] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=645516
Proposed patch (applied by the Owl Linux distrib
https://access.redhat.com/security/cve/cve-2011-3630https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=645516https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3630https://security-tracker.debian.org/tracker/CVE-2011-3630https://www.openwall.com/lists/oss-security/2011/10/20/6https://access.redhat.com/security/cve/cve-2011-3630https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=645516https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3630https://security-tracker.debian.org/tracker/CVE-2011-3630https://www.openwall.com/lists/oss-security/2011/10/20/6
2019-11-26
Published