Linux Kernel 64 Bit EXT3 Filesystem Extended Attribute Denial Of Service Vulnerability
BID:13680
Info
Linux Kernel 64 Bit EXT3 Filesystem Extended Attribute Denial Of Service Vulnerability
| Bugtraq ID: | 13680 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2005-0757 |
| Remote: | No |
| Local: | Yes |
| Published: | May 19 2005 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | This issue was announced in a vendor advisory. |
| Vulnerable: |
Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 3 Redhat Desktop 3.0 Linux kernel 2.6.12 -rc4 Linux kernel 2.6.11 .8 Linux kernel 2.6.11 .7 Linux kernel 2.6.11 .6 Linux kernel 2.6.11 .5 Linux kernel 2.6.11 -rc4 Linux kernel 2.6.11 -rc3 Linux kernel 2.6.11 -rc2 Linux kernel 2.6.11 Linux kernel 2.6.10 rc2 Linux kernel 2.6.10 Linux kernel 2.6.9 Linux kernel 2.6.8 rc3 Linux kernel 2.6.8 rc2 Linux kernel 2.6.8 rc1 Linux kernel 2.6.8 Linux kernel 2.6.7 rc1 Linux kernel 2.6.7 Linux kernel 2.6.6 rc1 Linux kernel 2.6.6 Linux kernel 2.6.5 Linux kernel 2.6.4 Linux kernel 2.6.3 Linux kernel 2.6.2 Linux kernel 2.6.1 -rc2 Linux kernel 2.6.1 -rc1 Linux kernel 2.6.1 Linux kernel 2.6 .10 Linux kernel 2.6 -test9-CVS Linux kernel 2.6 -test9 Linux kernel 2.6 -test8 Linux kernel 2.6 -test7 Linux kernel 2.6 -test6 Linux kernel 2.6 -test5 Linux kernel 2.6 -test4 Linux kernel 2.6 -test3 Linux kernel 2.6 -test2 Linux kernel 2.6 -test11 Linux kernel 2.6 -test10 Linux kernel 2.6 -test1 Linux kernel 2.6 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: | |
Discussion
Linux Kernel 64 Bit EXT3 Filesystem Extended Attribute Denial Of Service Vulnerability
The Linux Kernel is prone to a local denial of service vulnerability. Reports indicate the issue manifests on 64-bit platforms and is because of a flaw present in offset handling for the extended attribute file system code.
A local attacker may trigger this issue to crash the system kernel.
The Linux Kernel is prone to a local denial of service vulnerability. Reports indicate the issue manifests on 64-bit platforms and is because of a flaw present in offset handling for the extended attribute file system code.
A local attacker may trigger this issue to crash the system kernel.
Exploit / POC
Linux Kernel 64 Bit EXT3 Filesystem Extended Attribute Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Linux Kernel 64 Bit EXT3 Filesystem Extended Attribute Denial Of Service Vulnerability
Solution:
Red Hat has released advisory RHSA-2005:294-29 and fixes to address this is sue on Red Hat Linux Enterprise platforms. Customers who are affected by this issue are advised to apply the appropriate updates. Customers subscribed to the Red Hat Network may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see referenced advisory for additional information.
Debian advisory DSA 921-1 is available to address various issues affecting the Linux kernel. Please see the referenced advisory for more information.
Debian GNU/Linux has released advisory DSA 922-1, along with fixes to address multiple kernel issues. Please see the referenced advisory for further information.
---
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Red Hat has released advisory RHSA-2005:294-29 and fixes to address this is sue on Red Hat Linux Enterprise platforms. Customers who are affected by this issue are advised to apply the appropriate updates. Customers subscribed to the Red Hat Network may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see referenced advisory for additional information.
Debian advisory DSA 921-1 is available to address various issues affecting the Linux kernel. Please see the referenced advisory for more information.
Debian GNU/Linux has released advisory DSA 922-1, along with fixes to address multiple kernel issues. Please see the referenced advisory for further information.
---
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Linux Kernel 64 Bit EXT3 Filesystem Extended Attribute Denial Of Service Vulnerability
References:
References: