2.1

CVE-2014-9584

The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 3.18.2
Redhat ≫ Enterprise Linux Aus Version 6.6
Redhat ≫ Enterprise Linux Eus Version 6.6
Opensuse ≫ Evergreen Version 11.4
Opensuse ≫ Opensuse Version 13.1
Suse ≫ Linux Enterprise Desktop Version 12 Update -
Suse ≫ Linux Enterprise Real Time Extension Version 11 Update sp3
Suse ≫ Linux Enterprise Server Version 10 Update sp4 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp1 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp2 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 12 Update -
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Canonical ≫ Ubuntu Linux Version 10.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.10
Oracle ≫ Linux Version 5 Update -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.368
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html
Third Party Advisory
Mailing List
http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.html
Third Party Advisory
Mailing List
http://www.debian.org/security/2015/dsa-3128
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html
Third Party Advisory
Mailing List
http://rhn.redhat.com/errata/RHSA-2015-0864.html
Third Party Advisory
http://www.ubuntu.com/usn/USN-2513-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2514-1
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00020.html
Third Party Advisory
Mailing List
http://www.mandriva.com/security/advisories?name=MDVSA-2015:058
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00009.html
Third Party Advisory
Mailing List
http://www.ubuntu.com/usn/USN-2515-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2516-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2517-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2518-1
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1137.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1138.html
Third Party Advisory
http://www.ubuntu.com/usn/USN-2511-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2512-1
Third Party Advisory
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4e2024624e678f0ebb916e6192bd23c1f9fdf696
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.18.2
Vendor Advisory
http://www.openwall.com/lists/oss-security/2015/01/09/4
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/71883
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1180119
Third Party Advisory
Issue Tracking
https://github.com/torvalds/linux/commit/4e2024624e678f0ebb916e6192bd23c1f9fdf696
Patch
Third Party Advisory