4.7

CVE-2009-1046

The console selection feature in the Linux kernel 2.6.28 before 2.6.28.4, 2.6.25, and possibly earlier versions, when the UTF-8 console is used, allows physically proximate attackers to cause a denial of service (memory corruption) by selecting a small number of 3-byte UTF-8 characters, which triggers an "off-by-two memory error." NOTE: it is not clear whether this issue crosses privilege boundaries.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version2.6.25
LinuxLinux Kernel Version2.6.28
LinuxLinux Kernel Version2.6.28.1
LinuxLinux Kernel Version2.6.28.2
LinuxLinux Kernel Version2.6.28.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.78% 0.512
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.7 3.4 6.9
AV:L/AC:M/Au:N/C:N/I:N/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/34981
http://www.debian.org/security/2009/dsa-1787
http://www.ubuntu.com/usn/usn-751-1
http://secunia.com/advisories/34917
http://www.redhat.com/support/errata/RHSA-2009-0451.html
http://secunia.com/advisories/35121
http://www.debian.org/security/2009/dsa-1800
http://lists.openwall.net/linux-kernel/2009/01/30/333
Patch
http://lists.openwall.net/linux-kernel/2009/02/02/364
Patch
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.4
http://www.openwall.com/lists/oss-security/2009/02/12/10
http://www.openwall.com/lists/oss-security/2009/02/12/11
http://www.openwall.com/lists/oss-security/2009/02/12/9
http://www.securityfocus.com/bid/33672
Patch