CVE-2011-3630
Summary
| CVE | CVE-2011-3630 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-26 04:15:00 UTC |
| Updated | 2020-08-18 15:05:00 UTC |
| Description | Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory tree, and trick the local user into consolidating it, leading to hardlink executable crash, or, potentially arbitrary code execution with the privileges of the user running the hardlink executable. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Hardlink Project | Hardlink | All | All | All | All |
| Application | Hardlink Project | Hardlink | All | All | All | All |
| Operating System | Redhat | Enterprise Linux | 5.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 5.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 6.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Re: hardlink(1) has buffer overflows, is unsafe on changing trees | MISC | www.openwall.com | Mailing List, Third Party Advisory |
| CVE-2011-3630 | MISC | security-tracker.debian.org | Third Party Advisory |
| 746709 – (CVE-2011-3630) CVE-2011-3630 hardlink: Multiple stack-based buffer overflows when run on a tree with deeply nested directories | MISC | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| CVE-2011-3630 - Red Hat Customer Portal | MISC | access.redhat.com | Third Party Advisory |
| #645516 - hardlink: Security issue on changing trees - Debian Bug report logs | MISC | bugs.debian.org | Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.