CVE-2012-2319
published 2012-05-17CVE-2012-2319: Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3.3.5 allow local users to gain privileges via a crafted HFS plus…
PriorityP427high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.41%
34.0th percentile
Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3.3.5 allow local users to gain privileges via a crafted HFS plus filesystem, a related issue to CVE-2009-4020.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.17-1 (bookworm) | linux 3.2.17-1 (bookworm) |
| linux | linux_kernel | <= 3.3.3 | — |
| linux | linux_kernel | >= 0 < 3.2.17-1 | 3.2.17-1 |
| linux | linux_kernel | >= 0 < 3.2.17-1 | 3.2.17-1 |
| linux | linux_kernel | >= 0 < 3.2.17-1 | 3.2.17-1 |
| linux | linux_kernel | >= 0 < 3.2.17-1 | 3.2.17-1 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9w77-vr2w-558v: Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3
ghsa_unreviewed·2022-05-17·CVSS 7.8
CVE-2012-2319 [HIGH] GHSA-9w77-vr2w-558v: Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3
Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3.3.5 allow local users to gain privileges via a crafted HFS plus filesystem, a related issue to CVE-2009-4020.
OSV
CVE-2012-2319: Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3
osv·2012-05-17·CVSS 7.8
CVE-2012-2319 [HIGH] CVE-2012-2319: Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3
Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3.3.5 allow local users to gain privileges via a crafted HFS plus filesystem, a related issue to CVE-2009-4020.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-08-10·CVSS 4.6
CVE-2011-4131 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Adamson discovered a flaw in the Linux kernel's NFSv4 implementation.
A remote NFS server (attacker) could exploit this flaw to cause a denial of
service. (CVE-2011-4131)
Steve Grubb reported a flaw with Linux fscaps (file system base
capabilities) when used to increase the permissions of a process. For
application on which fscaps are in use a local attacker can disable address
space randomization to make attacking the process with raised privileges
easier. (CVE-2012-2123)
An error was discovered in the Linux kernel's network TUN/TAP device
implementation. A local user with access to the TUN/TAP interface (which is
not available to unprivileged users until granted by a root user)
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-06-29·CVSS 1.2
CVE-2012-2313 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Stephan Mueller reported a flaw in the Linux kernel's dl2k network driver's
handling of ioctls. An unprivileged local user could leverage this flaw to
cause a denial of service. (CVE-2012-2313)
Timo Warns reported multiple flaws in the Linux kernel's hfsplus
filesystem. An unprivileged local user could exploit these flaws to gain
root system priviliges. (CVE-2012-2319)
A flaw was discovered in the Linux kernel's NFSv4 (Network file system)
handling of ACLs (access control lists). A remote NFS server (attacker)
could cause a denial of service (OOPS). (CVE-2012-2375)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Linux kernel (Natty backport) vulnerabilities
vendor_ubuntu·2012-06-29·CVSS 1.2
CVE-2012-2313 [LOW] Linux kernel (Natty backport) vulnerabilities
Title: Linux kernel (Natty backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Stephan Mueller reported a flaw in the Linux kernel's dl2k network driver's
handling of ioctls. An unprivileged local user could leverage this flaw to
cause a denial of service. (CVE-2012-2313)
Timo Warns reported multiple flaws in the Linux kernel's hfsplus
filesystem. An unprivileged local user could exploit these flaws to gain
root system priviliges. (CVE-2012-2319)
A flaw was discovered in the Linux kernel's NFSv4 (Network file system)
handling of ACLs (access control lists). A remote NFS server (attacker)
could cause a denial of service (OOPS). (CVE-2012-2375)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2012-06-29·CVSS 1.2
CVE-2012-2313 [LOW] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Stephan Mueller reported a flaw in the Linux kernel's dl2k network driver's
handling of ioctls. An unprivileged local user could leverage this flaw to
cause a denial of service. (CVE-2012-2313)
Timo Warns reported multiple flaws in the Linux kernel's hfsplus
filesystem. An unprivileged local user could exploit these flaws to gain
root system priviliges. (CVE-2012-2319)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-06-29·CVSS 1.2
CVE-2012-2313 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Stephan Mueller reported a flaw in the Linux kernel's dl2k network driver's
handling of ioctls. An unprivileged local user could leverage this flaw to
cause a denial of service. (CVE-2012-2313)
Timo Warns reported multiple flaws in the Linux kernel's hfsplus
filesystem. An unprivileged local user could exploit these flaws to gain
root system priviliges. (CVE-2012-2319)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-06-15·CVSS 4.6
CVE-2011-4131 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Adamson discovered a flaw in the Linux kernel's NFSv4 implementation.
A remote NFS server (attacker) could exploit this flaw to cause a denial of
service. (CVE-2011-4131)
A flaw was discovered in the Linux kernel's KVM (kernel virtual machine).
An administrative user in the guest OS could leverage this flaw to cause a
denial of service in the host OS. (CVE-2012-2121)
Schacher Raindel discovered a flaw in the Linux kernel's memory handling
when hugetlb is enabled. An unprivileged local attacker could exploit this
flaw to cause a denial of service and potentially gain higher privileges.
(CVE-2012-2133)
Stephan Mueller reported a flaw in the Linux kernel's dl2k network driver's
han
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-06-13·CVSS 4.9
CVE-2012-2121 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's KVM (kernel virtual machine).
An administrative user in the guest OS could leverage this flaw to cause a
denial of service in the host OS. (CVE-2012-2121)
Schacher Raindel discovered a flaw in the Linux kernel's memory handling
when hugetlb is enabled. An unprivileged local attacker could exploit this
flaw to cause a denial of service and potentially gain higher privileges.
(CVE-2012-2133)
Stephan Mueller reported a flaw in the Linux kernel's dl2k network driver's
handling of ioctls. An unprivileged local user could leverage this flaw to
cause a denial of service. (CVE-2012-2313)
Timo Warns reported multiple flaws in the Linux kernel's hfsp
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-06-13·CVSS 4.9
CVE-2012-2121 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's KVM (kernel virtual machine).
An administrative user in the guest OS could leverage this flaw to cause a
denial of service in the host OS. (CVE-2012-2121)
Schacher Raindel discovered a flaw in the Linux kernel's memory handling
when hugetlb is enabled. An unprivileged local attacker could exploit this
flaw to cause a denial of service and potentially gain higher privileges.
(CVE-2012-2133)
Stephan Mueller reported a flaw in the Linux kernel's dl2k network driver's
handling of ioctls. An unprivileged local user could leverage this flaw to
cause a denial of service. (CVE-2012-2313)
Timo Warns reported multiple flaws in the Linux kernel's hfsplus
file
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-06-12·CVSS 4.6
CVE-2011-4131 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Adamson discovered a flaw in the Linux kernel's NFSv4 implementation.
A remote NFS server (attacker) could exploit this flaw to cause a denial of
service. (CVE-2011-4131)
A flaw was discovered in the Linux kernel's KVM (kernel virtual machine).
An administrative user in the guest OS could leverage this flaw to cause a
denial of service in the host OS. (CVE-2012-2121)
Schacher Raindel discovered a flaw in the Linux kernel's memory handling
when hugetlb is enabled. An unprivileged local attacker could exploit this
flaw to cause a denial of service and potentially gain higher privileges.
(CVE-2012-2133)
Stephan Mueller reported a flaw in the Linux kernel's dl2k network driver's
handling of
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2012-06-12·CVSS 4.6
CVE-2011-4131 [MEDIUM] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Adamson discovered a flaw in the Linux kernel's NFSv4 implementation.
A remote NFS server (attacker) could exploit this flaw to cause a denial of
service. (CVE-2011-4131)
A flaw was discovered in the Linux kernel's KVM (kernel virtual machine).
An administrative user in the guest OS could leverage this flaw to cause a
denial of service in the host OS. (CVE-2012-2121)
Schacher Raindel discovered a flaw in the Linux kernel's memory handling
when hugetlb is enabled. An unprivileged local attacker could exploit this
flaw to cause a denial of service and potentially gain higher privileges.
(CVE-2012-2133)
Stephan Mueller reported a flaw in the Linux kernel's dl2k network d
Red Hat
kernel: Buffer overflow in the HFS plus filesystem (different issue than CVE-2009-4020)
vendor_redhat·2012-05-04·CVSS 7.8
CVE-2012-2319 [HIGH] CWE-119 kernel: Buffer overflow in the HFS plus filesystem (different issue than CVE-2009-4020)
kernel: Buffer overflow in the HFS plus filesystem (different issue than CVE-2009-4020)
Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3.3.5 allow local users to gain privileges via a crafted HFS plus filesystem, a related issue to CVE-2009-4020.
Statement: This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG, as those versions do not have CONFIG_HFSPLUS_FS option enabled.
The Red Hat Security Response Team has rated this issue as having low security impact. A future kernel updates in Red Hat Enterprise Linux 5 may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
P
Debian
CVE-2012-2319: linux - Multiple buffer overflows in the hfsplus filesystem implementation in the Linux ...
vendor_debian·2012·CVSS 7.8
CVE-2012-2319 [HIGH] CVE-2012-2319: linux - Multiple buffer overflows in the hfsplus filesystem implementation in the Linux ...
Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3.3.5 allow local users to gain privileges via a crafted HFS plus filesystem, a related issue to CVE-2009-4020.
Scope: local
bookworm: resolved (fixed in 3.2.17-1)
bullseye: resolved (fixed in 3.2.17-1)
forky: resolved (fixed in 3.2.17-1)
sid: resolved (fixed in 3.2.17-1)
trixie: resolved (fixed in 3.2.17-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2319 kernel: Buffer overflow in the HFS plus filesystem (different issue than CVE-2009-4020) [fedora-all]
bugzilla·2012-05-09·CVSS 7.8
CVE-2012-2319 [HIGH] CVE-2012-2319 kernel: Buffer overflow in the HFS plus filesystem (different issue than CVE-2009-4020) [fedora-all]
CVE-2012-2319 kernel: Buffer overflow in the HFS plus filesystem (different issue than CVE-2009-4020) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedora
Bugzilla
CVE-2012-2319 kernel: Buffer overflow in the HFS plus filesystem (different issue than CVE-2009-4020)
bugzilla·2012-05-07·CVSS 7.8
CVE-2012-2319 [HIGH] CVE-2012-2319 kernel: Buffer overflow in the HFS plus filesystem (different issue than CVE-2009-4020)
CVE-2012-2319 kernel: Buffer overflow in the HFS plus filesystem (different issue than CVE-2009-4020)
Previously Common Vulnerabilities and Exposures assigned an identifier of CVE-2009-4020 to the following vulnerability:
Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical File System (HFS) filesystem, related to the hfs_readdir function in fs/hfs/dir.c.
Recently:
[1] http://www.openwall.com/lists/oss-security/2012/05/07/3
Timo Warns pointed out similar flaws exists in the HFS plus file system.
Relevant upstream patch:
[2] http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=6f24f892871acc47b40dd594c63606a17c714f77
Discussion:
The CVE identifier of CVE-
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6f24f892871acc47b40dd594c63606a17c714f77http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1323.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1347.htmlhttp://secunia.com/advisories/50811http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.3.5http://www.openwall.com/lists/oss-security/2012/05/07/11https://bugzilla.redhat.com/show_bug.cgi?id=819471https://github.com/torvalds/linux/commit/6f24f892871acc47b40dd594c63606a17c714f77http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6f24f892871acc47b40dd594c63606a17c714f77http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1323.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1347.htmlhttp://secunia.com/advisories/50811http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.3.5http://www.openwall.com/lists/oss-security/2012/05/07/11https://bugzilla.redhat.com/show_bug.cgi?id=819471https://github.com/torvalds/linux/commit/6f24f892871acc47b40dd594c63606a17c714f77
2012-05-17
Published