2.1

CVE-2008-3528

Exploit
The error-reporting functionality in (1) fs/ext2/dir.c, (2) fs/ext3/dir.c, and possibly (3) fs/ext4/dir.c in the Linux kernel 2.6.26.5 does not limit the number of printk console messages that report directory corruption, which allows physically proximate attackers to cause a denial of service (temporary system hang) by mounting a filesystem that has corrupted dir->i_size and dir->i_blocks values and performing (a) read or (b) write operations.  NOTE: there are limited scenarios in which this crosses privilege boundaries.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version2.6.26.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.403
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/37471
Vendor Advisory
http://www.securityfocus.com/archive/1/507985/100/0/threaded
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
http://www.vupen.com/english/advisories/2009/3316
Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html
http://secunia.com/advisories/32759
Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2008-0972.html
http://secunia.com/advisories/32799
Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00007.html
http://secunia.com/advisories/32356
http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00008.html
http://secunia.com/advisories/32370
http://secunia.com/advisories/33586
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2009-0009.html
http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00010.html
http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00000.html
http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00001.html
http://lkml.org/lkml/2008/9/13/98
Exploit
http://lkml.org/lkml/2008/9/13/99
Exploit
http://lkml.org/lkml/2008/9/17/371
http://secunia.com/advisories/32509
Vendor Advisory
http://secunia.com/advisories/32709
Vendor Advisory
http://secunia.com/advisories/32998
Vendor Advisory
http://secunia.com/advisories/33180
Vendor Advisory
http://secunia.com/advisories/33758
Vendor Advisory
http://wiki.rpath.com/Advisories:rPSA-2008-0316
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0316
http://www.debian.org/security/2008/dsa-1681
http://www.debian.org/security/2008/dsa-1687
http://www.mandriva.com/security/advisories?name=MDVSA-2008:224
http://www.openwall.com/lists/oss-security/2008/09/18/2
http://www.redhat.com/support/errata/RHSA-2009-0326.html
http://www.securityfocus.com/archive/1/498285/100/0/threaded
http://www.ubuntu.com/usn/usn-662-1
https://bugzilla.redhat.com/show_bug.cgi?id=459577
https://exchange.xforce.ibmcloud.com/vulnerabilities/45720
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10852
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8642