CVE-2014-9730
published 2015-08-31CVE-2014-9730: The udf_pc_to_char function in fs/udf/symlink.c in the Linux kernel before 3.18.2 relies on component lengths that are unused, which allows local users to…
PriorityP414medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.41%
33.8th percentile
The udf_pc_to_char function in fs/udf/symlink.c in the Linux kernel before 3.18.2 relies on component lengths that are unused, which allows local users to cause a denial of service (system crash) via a crafted UDF filesystem image.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.16.7-ckt4-1 (bookworm) | linux 3.16.7-ckt4-1 (bookworm) |
| linux | linux_kernel | <= 3.18.1 | — |
| linux | linux_kernel | >= 0 < 3.16.7-ckt4-1 | 3.16.7-ckt4-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt4-1 | 3.16.7-ckt4-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt4-1 | 3.16.7-ckt4-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt4-1 | 3.16.7-ckt4-1 |
| linux | linux_kernel | >= 0 < 3.13.0-48.80 | 3.13.0-48.80 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_ubuntu7.2HIGH
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g26h-h44q-fqf3: The udf_pc_to_char function in fs/udf/symlink
ghsa_unreviewed·2022-05-17
CVE-2014-9730 [MEDIUM] GHSA-g26h-h44q-fqf3: The udf_pc_to_char function in fs/udf/symlink
The udf_pc_to_char function in fs/udf/symlink.c in the Linux kernel before 3.18.2 relies on component lengths that are unused, which allows local users to cause a denial of service (system crash) via a crafted UDF filesystem image.
OSV
CVE-2014-9730: The udf_pc_to_char function in fs/udf/symlink
osv·2015-08-31·CVSS 4.9
CVE-2014-9730 [MEDIUM] CVE-2014-9730: The udf_pc_to_char function in fs/udf/symlink
The udf_pc_to_char function in fs/udf/symlink.c in the Linux kernel before 3.18.2 relies on component lengths that are unused, which allows local users to cause a denial of service (system crash) via a crafted UDF filesystem image.
OSV
linux vulnerabilities
osv·2015-03-24·CVSS 2.1
CVE-2015-0274 [LOW] linux vulnerabilities
linux vulnerabilities
Eric Windisch discovered flaw in how the Linux kernel's XFS file system
replaces remote attributes. A local access with access to an XFS file
system could exploit this flaw to escalate their privileges.
(CVE-2015-0274)
A flaw was discovered in the automatic loading of modules in the crypto
subsystem of the Linux kernel. A local user could exploit this flaw to load
installed kernel modules, increasing the attack surface and potentially
using this to gain administrative privileges. (CVE-2013-7421)
The Linux kernel's splice system call did not correctly validate its
parameters. A local, unprivileged user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-7822)
A flaw was discovered in the crypto subsystem when screening module names
for au
OSV
linux-lts-utopic vulnerabilities
osv·2015-02-26·CVSS 2.1
CVE-2015-0239 [LOW] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
A flaw was discovered in the Kernel Virtual Machine's (KVM) emulation of
the SYSTENTER instruction when the guest OS does not initialize the
SYSENTER MSRs. A guest OS user could exploit this flaw to cause a denial of
service of the guest OS (crash) or potentially gain privileges on the guest
OS. (CVE-2015-0239)
Andy Lutomirski discovered an information leak in the Linux kernel's Thread
Local Storage (TLS) implementation allowing users to bypass the espfix to
obtain information that could be used to bypass the Address Space Layout
Randomization (ASLR) protection mechanism. A local user could exploit this
flaw to obtain potentially sensitive information from kernel memory.
(CVE-2014-8133)
A restriction bypass was discovered in iptables when conntrack rules
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-03-24·CVSS 2.1
CVE-2013-7421 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Eric Windisch discovered flaw in how the Linux kernel's XFS file system
replaces remote attributes. A local access with access to an XFS file
system could exploit this flaw to escalate their privileges.
(CVE-2015-0274)
A flaw was discovered in the automatic loading of modules in the crypto
subsystem of the Linux kernel. A local user could exploit this flaw to load
installed kernel modules, increasing the attack surface and potentially
using this to gain administrative privileges. (CVE-2013-7421)
The Linux kernel's splice system call did not correctly validate its
parameters. A local, unprivileged user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-7822)
A flaw
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-03-24·CVSS 2.1
CVE-2013-7421 [LOW] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Eric Windisch discovered flaw in how the Linux kernel's XFS file system
replaces remote attributes. A local access with access to an XFS file
system could exploit this flaw to escalate their privileges.
(CVE-2015-0274)
A flaw was discovered in the automatic loading of modules in the crypto
subsystem of the Linux kernel. A local user could exploit this flaw to load
installed kernel modules, increasing the attack surface and potentially
using this to gain administrative privileges. (CVE-2013-7421)
The Linux kernel's splice system call did not correctly validate its
parameters. A local, unprivileged user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2015-03-24·CVSS 7.2
CVE-2014-7822 [HIGH] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
The Linux kernel's splice system call did not correctly validate its
parameters. A local, unprivileged user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-7822)
A flaw was discovered in how Thread Local Storage (TLS) is handled by the
task switching function in the Linux kernel for x86_64 based machines. A
local user could exploit this flaw to bypass the Address Space Layout
Radomization (ASLR) protection mechanism. (CVE-2014-9419)
Dmitry Chernenkov discovered a buffer overflow in eCryptfs' encrypted file
name decoding. A local unprivileged user could exploit this flaw to cause a
denial of service (system crash) or potentially gain administrative
privil
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-03-24·CVSS 7.2
CVE-2014-7822 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
The Linux kernel's splice system call did not correctly validate its
parameters. A local, unprivileged user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-7822)
A flaw was discovered in how Thread Local Storage (TLS) is handled by the
task switching function in the Linux kernel for x86_64 based machines. A
local user could exploit this flaw to bypass the Address Space Layout
Radomization (ASLR) protection mechanism. (CVE-2014-9419)
Dmitry Chernenkov discovered a buffer overflow in eCryptfs' encrypted file
name decoding. A local unprivileged user could exploit this flaw to cause a
denial of service (system crash) or potentially gain administrative
privileges. (C
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-02-26·CVSS 2.1
CVE-2014-8133 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Kernel Virtual Machine's (KVM) emulation of
the SYSTENTER instruction when the guest OS does not initialize the
SYSENTER MSRs. A guest OS user could exploit this flaw to cause a denial of
service of the guest OS (crash) or potentially gain privileges on the guest
OS. (CVE-2015-0239)
Andy Lutomirski discovered an information leak in the Linux kernel's Thread
Local Storage (TLS) implementation allowing users to bypass the espfix to
obtain information that could be used to bypass the Address Space Layout
Randomization (ASLR) protection mechanism. A local user could exploit this
flaw to obtain potentially sensitive information from kernel memory.
(CVE-2014-8133)
A res
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-02-26·CVSS 2.1
CVE-2014-8133 [LOW] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Kernel Virtual Machine's (KVM) emulation of
the SYSTENTER instruction when the guest OS does not initialize the
SYSENTER MSRs. A guest OS user could exploit this flaw to cause a denial of
service of the guest OS (crash) or potentially gain privileges on the guest
OS. (CVE-2015-0239)
Andy Lutomirski discovered an information leak in the Linux kernel's Thread
Local Storage (TLS) implementation allowing users to bypass the espfix to
obtain information that could be used to bypass the Address Space Layout
Randomization (ASLR) protection mechanism. A local user could exploit this
flaw to obtain potentially sensitive information from kernel memory.
(CVE-2014
Red Hat
Kernel: fs: udf: heap overflow in __udf_adinicb_readpage
vendor_redhat·2014-12-19·CVSS 4.9
CVE-2014-9730 [MEDIUM] CWE-122 Kernel: fs: udf: heap overflow in __udf_adinicb_readpage
Kernel: fs: udf: heap overflow in __udf_adinicb_readpage
The udf_pc_to_char function in fs/udf/symlink.c in the Linux kernel before 3.18.2 relies on component lengths that are unused, which allows local users to cause a denial of service (system crash) via a crafted UDF filesystem image.
A symlink size validation was missing in Linux kernels built with UDF file system (CONFIG_UDF_FS) support, allowing the corruption of kernel memory. An attacker able to mount a corrupted/malicious UDF file system image could cause the kernel to crash.
Statement: This issue affects the versions of the Linux kernel as shipped with
Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2.
Mitigation: The UDF filesystem is enabled via loading the UDF kernel module. The kernel module can be prevented f
Debian
CVE-2014-9730: linux - The udf_pc_to_char function in fs/udf/symlink.c in the Linux kernel before 3.18....
vendor_debian·2014·CVSS 4.9
CVE-2014-9730 [MEDIUM] CVE-2014-9730: linux - The udf_pc_to_char function in fs/udf/symlink.c in the Linux kernel before 3.18....
The udf_pc_to_char function in fs/udf/symlink.c in the Linux kernel before 3.18.2 relies on component lengths that are unused, which allows local users to cause a denial of service (system crash) via a crafted UDF filesystem image.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt4-1)
bullseye: resolved (fixed in 3.16.7-ckt4-1)
forky: resolved (fixed in 3.16.7-ckt4-1)
sid: resolved (fixed in 3.16.7-ckt4-1)
trixie: resolved (fixed in 3.16.7-ckt4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9728 CVE-2014-9729 CVE-2014-9730 Kernel: fs: udf: heap overflow in __udf_adinicb_readpage
bugzilla·2015-06-04·CVSS 4.9
CVE-2014-9728 [MEDIUM] CVE-2014-9728 CVE-2014-9729 CVE-2014-9730 Kernel: fs: udf: heap overflow in __udf_adinicb_readpage
CVE-2014-9728 CVE-2014-9729 CVE-2014-9730 Kernel: fs: udf: heap overflow in __udf_adinicb_readpage
Linux kernel built with the UDF file system(CONFIG_UDF_FS) support is
vulnerable to a crash. It could occur while reading from a corrupted/malicious
udf file system image.
An unprivileged user could use this flaw to crash the kernel resulting in DoS.
Upstream fixes:
-> https://git.kernel.org/linus/e159332b9af4b04d882dbcfe1bb0117f0a6d4b58
-> https://git.kernel.org/linus/e237ec37ec154564f8690c5bd1795339955eeef9
-> https://git.kernel.org/linus/a1d47b262952a45aae62bd49cfaf33dd76c11a2c
Reference:
-> http://www.openwall.com/lists/oss-security/2015/06/03/14
Discussion:
Statement:
This issue affects the versions of the Linux kernel as shipped with
Red Hat Enterprise Linux 5, 6, 7 and Red Hat E
Bugzilla
CVE-2014-2283 wireshark: RLC dissector crash (wnpa-sec-2014-03)
bugzilla·2014-03-08·CVSS 4.3
CVE-2014-2283 [MEDIUM] CVE-2014-2283 wireshark: RLC dissector crash (wnpa-sec-2014-03)
CVE-2014-2283 wireshark: RLC dissector crash (wnpa-sec-2014-03)
It was reported that Wireshark's RLC dissector could crash. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
This is reported to affect Wireshark versions 1.10.0 to 1.10.5 and 1.8.0 to 1.8.12. It is fixed in 1.10.6 and 1.8.13.
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9730
External References:
http://www.wireshark.org/security/wnpa-sec-2014-03.html
Discussion:
Created wireshark tracking bugs for this issue:
Affects: fedora-all [bug 1074118]
---
Depends on: 1074904 <- Parent bug addresses RHEL-5.10.z
Using wireshark-1.0.15-5.el5
There is no such dissector, as the patch modifies: epan/dissectors/packet-r
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e237ec37ec154564f8690c5bd1795339955eeef9http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00049.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.18.2http://www.openwall.com/lists/oss-security/2015/06/02/7http://www.securityfocus.com/bid/74964https://bugzilla.redhat.com/show_bug.cgi?id=1228229https://github.com/torvalds/linux/commit/e237ec37ec154564f8690c5bd1795339955eeef9http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e237ec37ec154564f8690c5bd1795339955eeef9http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00049.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.18.2http://www.openwall.com/lists/oss-security/2015/06/02/7http://www.securityfocus.com/bid/74964https://bugzilla.redhat.com/show_bug.cgi?id=1228229https://github.com/torvalds/linux/commit/e237ec37ec154564f8690c5bd1795339955eeef9
2015-08-31
Published