Linux Kernel Multiple Unspecified ISO9660 Filesystem Handling Vulnerabilities
BID:12837
Info
Linux Kernel Multiple Unspecified ISO9660 Filesystem Handling Vulnerabilities
| Bugtraq ID: | 12837 |
| Class: | Unknown |
| CVE: |
CVE-2005-0815 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 17 2005 12:00AM |
| Updated: | Mar 01 2007 10:26PM |
| Credit: | Discovery of these vulnerabilities is credited to Michal Zalewski <[email protected]>. |
| Vulnerable: |
Ubuntu Ubuntu Linux 4.1 ppc Ubuntu Ubuntu Linux 4.1 ia64 Ubuntu Ubuntu Linux 4.1 ia32 SGI ProPack 3.0 SP6 SGI ProPack 3.0 SP5 SGI ProPack 3.0 SP4 SGI ProPack 3.0 SP3 SGI ProPack 3.0 SP2 SGI ProPack 3.0 SP1 SGI ProPack 3.0 Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Linux kernel 2.6.11 -rc4 Linux kernel 2.6.11 -rc3 Linux kernel 2.6.11 -rc2 Linux kernel 2.6.11 Linux kernel 2.6.10 rc2 Linux kernel 2.6.10 Linux kernel 2.6.9 Linux kernel 2.6.8 rc3 Linux kernel 2.6.8 rc2 Linux kernel 2.6.8 rc1 Linux kernel 2.6.8 Linux kernel 2.6.7 rc1 Linux kernel 2.6.7 Linux kernel 2.6.6 rc1 Linux kernel 2.6.6 Linux kernel 2.6.5 Linux kernel 2.6.4 Linux kernel 2.6.3 Linux kernel 2.6.2 Linux kernel 2.6.1 -rc2 Linux kernel 2.6.1 -rc1 Linux kernel 2.6.1 Linux kernel 2.6 .10 Linux kernel 2.6 -test9-CVS Linux kernel 2.6 -test9 Linux kernel 2.6 -test8 Linux kernel 2.6 -test7 Linux kernel 2.6 -test6 Linux kernel 2.6 -test5 Linux kernel 2.6 -test4 Linux kernel 2.6 -test3 Linux kernel 2.6 -test2 Linux kernel 2.6 -test11 Linux kernel 2.6 -test10 Linux kernel 2.6 -test1 Linux kernel 2.6 Linux kernel 2.4.29 -rc2 Linux kernel 2.4.29 -rc1 Linux kernel 2.4.28 Linux kernel 2.4.27 -pre5 Linux kernel 2.4.27 -pre4 Linux kernel 2.4.27 -pre3 Linux kernel 2.4.27 -pre2 Linux kernel 2.4.27 -pre1 Linux kernel 2.4.27 Linux kernel 2.4.26 Linux kernel 2.4.25 Linux kernel 2.4.24 -ow1 Linux kernel 2.4.24 Linux kernel 2.4.23 -pre9 Linux kernel 2.4.23 -ow2 Linux kernel 2.4.23 Linux kernel 2.4.22 Linux kernel 2.4.21 pre7 Linux kernel 2.4.21 pre4 Linux kernel 2.4.21 pre1 Linux kernel 2.4.21 Linux kernel 2.4.20 Linux kernel 2.4.19 -pre6 Linux kernel 2.4.19 -pre5 Linux kernel 2.4.19 -pre4 Linux kernel 2.4.19 -pre3 Linux kernel 2.4.19 -pre2 Linux kernel 2.4.19 -pre1 Linux kernel 2.4.19 Linux kernel 2.4.18 pre-8 Linux kernel 2.4.18 pre-7 Linux kernel 2.4.18 pre-6 Linux kernel 2.4.18 pre-5 Linux kernel 2.4.18 pre-4 Linux kernel 2.4.18 pre-3 Linux kernel 2.4.18 pre-2 Linux kernel 2.4.18 pre-1 Linux kernel 2.4.18 x86 Linux kernel 2.4.18 Linux kernel 2.4.17 Linux kernel 2.4.16 Linux kernel 2.4.15 Linux kernel 2.4.14 Linux kernel 2.4.13 Linux kernel 2.4.12 Linux kernel 2.4.11 Linux kernel 2.4.10 Linux kernel 2.4.9 Linux kernel 2.4.8 Linux kernel 2.4.7 Linux kernel 2.4.6 Linux kernel 2.4.5 Linux kernel 2.4.4 Linux kernel 2.4.3 Linux kernel 2.4.2 Linux kernel 2.4.1 Linux kernel 2.4 .0-test9 Linux kernel 2.4 .0-test8 Linux kernel 2.4 .0-test7 Linux kernel 2.4 .0-test6 Linux kernel 2.4 .0-test5 Linux kernel 2.4 .0-test4 Linux kernel 2.4 .0-test3 Linux kernel 2.4 .0-test2 Linux kernel 2.4 .0-test12 Linux kernel 2.4 .0-test11 Linux kernel 2.4 .0-test10 Linux kernel 2.4 .0-test1 Linux kernel 2.4 |
| Not Vulnerable: | |
Discussion
Linux Kernel Multiple Unspecified ISO9660 Filesystem Handling Vulnerabilities
The Linux kernel is reported prone to multiple vulnerabilities that occur because of "range-checking flaws" present in the ISO9660 handling routines.
An attacker may exploit these issues to trigger kernel-based memory corruption. Ultimately, the attacker may be able to execute arbitrary malicious code with ring-zero privileges.
These vulnerabilities are reported to be present in the ISO9660 filesystem handler including Rock Ridge and Juliet extensions for the Linux kernel up to and including version 2.6.11.
The Linux kernel is reported prone to multiple vulnerabilities that occur because of "range-checking flaws" present in the ISO9660 handling routines.
An attacker may exploit these issues to trigger kernel-based memory corruption. Ultimately, the attacker may be able to execute arbitrary malicious code with ring-zero privileges.
These vulnerabilities are reported to be present in the ISO9660 filesystem handler including Rock Ridge and Juliet extensions for the Linux kernel up to and including version 2.6.11.
Exploit / POC
Linux Kernel Multiple Unspecified ISO9660 Filesystem Handling Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
The following test script is available:
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
The following test script is available:
Solution / Fix
Linux Kernel Multiple Unspecified ISO9660 Filesystem Handling Vulnerabilities
Solution:
Please see the referenced advisories for details on obtaining and applying fixes.
Redhat Fedora Core1
Linux kernel 2.4.18
Linux kernel 2.4.25
Linux kernel 2.6.9
Solution:
Please see the referenced advisories for details on obtaining and applying fixes.
Redhat Fedora Core1
-
RedHat kernel-2.4.22-1.2199.5.legacy.nptl.athlon.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/kernel-2.4.22-1 .2199.5.legacy.nptl.athlon.rpm -
RedHat kernel-2.4.22-1.2199.5.legacy.nptl.i586.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/kernel-2.4.22-1 .2199.5.legacy.nptl.i586.rpm -
RedHat kernel-2.4.22-1.2199.5.legacy.nptl.i686.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/kernel-2.4.22-1 .2199.5.legacy.nptl.i686.rpm -
RedHat kernel-BOOT-2.4.22-1.2199.5.legacy.nptl.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/kernel-BOOT-2.4 .22-1.2199.5.legacy.nptl.i386.rpm -
RedHat kernel-doc-2.4.22-1.2199.5.legacy.nptl.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/kernel-doc-2.4. 22-1.2199.5.legacy.nptl.i386.rpm -
RedHat kernel-smp-2.4.22-1.2199.5.legacy.nptl.athlon.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/kernel-smp-2.4. 22-1.2199.5.legacy.nptl.athlon.rpm -
RedHat kernel-smp-2.4.22-1.2199.5.legacy.nptl.i586.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/kernel-smp-2.4. 22-1.2199.5.legacy.nptl.i586.rpm -
RedHat kernel-smp-2.4.22-1.2199.5.legacy.nptl.i686.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/kernel-smp-2.4. 22-1.2199.5.legacy.nptl.i686.rpm -
RedHat kernel-source-2.4.22-1.2199.5.legacy.nptl.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/kernel-source-2 .4.22-1.2199.5.legacy.nptl.i386.rpm
Linux kernel 2.4.18
-
Mandriva kernel-2.6.3.31mdk-1-1mdk.i586.rpm
Multi Network Firewall 2.0:
http://www.mandriva.com/en/download -
Mandriva kernel-2.6.3.31mdk-1-1mdk.src.rpm
Multi Network Firewall 2.0:
http://www.mandriva.com/en/download -
Mandriva kernel-i686-up-4GB-2.6.3.31mdk-1-1mdk.i586.rpm
Multi Network Firewall 2.0:
http://www.mandriva.com/en/download -
Mandriva kernel-p3-smp-64GB-2.6.3.31mdk-1-1mdk.i586.rpm
Multi Network Firewall 2.0:
http://www.mandriva.com/en/download -
Mandriva kernel-secure-2.6.3.31mdk-1-1mdk.i586.rpm
Multi Network Firewall 2.0:
http://www.mandriva.com/en/download -
Mandriva kernel-smp-2.6.3.31mdk-1-1mdk.i586.rpm
Multi Network Firewall 2.0:
http://www.mandriva.com/en/download
Linux kernel 2.4.25
-
Mandriva kernel-2.6.3.31mdk-1-1mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva kernel-2.6.3.31mdk-1-1mdk.src.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva kernel-2.6.3.31mdk-1-1mdk.x86_64.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva kernel-BOOT-2.6.3.31mdk-1-1mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva kernel-BOOT-2.6.3.31mdk-1-1mdk.x86_64.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva kernel-enterprise-2.6.3.31mdk-1-1mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva kernel-i686-up-4GB-2.6.3.31mdk-1-1mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva kernel-p3-smp-64GB-2.6.3.31mdk-1-1mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva kernel-secure-2.6.3.31mdk-1-1mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva kernel-secure-2.6.3.31mdk-1-1mdk.x86_64.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva kernel-smp-2.6.3.31mdk-1-1mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva kernel-smp-2.6.3.31mdk-1-1mdk.x86_64.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
Linux kernel 2.6.9
-
Fedora kernel-2.6.11-1.14_FC3.i586.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora kernel-2.6.11-1.14_FC3.i686.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora kernel-2.6.11-1.14_FC3.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora kernel-debuginfo-2.6.11-1.14_FC3.i586.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora kernel-debuginfo-2.6.11-1.14_FC3.i686.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora kernel-debuginfo-2.6.11-1.14_FC3.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora kernel-doc-2.6.11-1.14_FC3.noarch.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora kernel-smp-2.6.11-1.14_FC3.i586.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora kernel-smp-2.6.11-1.14_FC3.i686.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora kernel-smp-2.6.11-1.14_FC3.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
References
Linux Kernel Multiple Unspecified ISO9660 Filesystem Handling Vulnerabilities
References:
References:
- 20060402-01-U - SGI ProPack3 Kernel Update #21 - Security and other fixes (SGI)
- RHSA-2005:366-19 - kernel security update (RedHat)
- RHSA-2005:663-19 - Updated kernel packages available for Red Hat Enterprise Linu (RedHat)
- RHSA-2006:0190-5 - kernel security update (RedHat)
- RHSA-2006:0191-9 - kernel security update (RedHat)
- Linux ISO9660 handling flaws (Michal Zalewski
)