CVE-2009-4020

Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical File System (HFS) filesystem, related to the hfs_readdir function in fs/hfs/dir.c.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html
http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00007.html
http://marc.info/?l=linux-mm-commits&m=125987755823047&w=2
http://secunia.com/advisories/38276
http://secunia.com/advisories/39742
http://support.avaya.com/css/P8/documents/100073666
http://userweb.kernel.org/~akpm/mmotm/broken-out/hfs-fix-a-potential-buffer-overflow.patch Patch
http://www.debian.org/security/2010/dsa-2005
http://www.novell.com/linux/security/advisories/2010_23_kernel.html
http://www.openwall.com/lists/oss-security/2009/12/04/1
https://bugzilla.redhat.com/show_bug.cgi?id=540736
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10091
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6750
https://rhn.redhat.com/errata/RHSA-2010-0046.html
https://rhn.redhat.com/errata/RHSA-2010-0095.html
http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html
http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00007.html
http://marc.info/?l=linux-mm-commits&m=125987755823047&w=2
http://secunia.com/advisories/38276
http://secunia.com/advisories/39742
http://support.avaya.com/css/P8/documents/100073666
http://userweb.kernel.org/~akpm/mmotm/broken-out/hfs-fix-a-potential-buffer-overflow.patch Patch
http://www.debian.org/security/2010/dsa-2005
http://www.novell.com/linux/security/advisories/2010_23_kernel.html
http://www.openwall.com/lists/oss-security/2009/12/04/1
https://bugzilla.redhat.com/show_bug.cgi?id=540736
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10091
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6750
https://rhn.redhat.com/errata/RHSA-2010-0046.html
https://rhn.redhat.com/errata/RHSA-2010-0095.html
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:2.6.32:*:*:*:*:*:*:*

History

21 Nov 2024, 01:08

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html - () http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html -
References () http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00007.html - () http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00007.html -
References () http://marc.info/?l=linux-mm-commits&m=125987755823047&w=2 - () http://marc.info/?l=linux-mm-commits&m=125987755823047&w=2 -
References () http://secunia.com/advisories/38276 - () http://secunia.com/advisories/38276 -
References () http://secunia.com/advisories/39742 - () http://secunia.com/advisories/39742 -
References () http://support.avaya.com/css/P8/documents/100073666 - () http://support.avaya.com/css/P8/documents/100073666 -
References () http://userweb.kernel.org/~akpm/mmotm/broken-out/hfs-fix-a-potential-buffer-overflow.patch - Patch () http://userweb.kernel.org/~akpm/mmotm/broken-out/hfs-fix-a-potential-buffer-overflow.patch - Patch
References () http://www.debian.org/security/2010/dsa-2005 - () http://www.debian.org/security/2010/dsa-2005 -
References () http://www.novell.com/linux/security/advisories/2010_23_kernel.html - () http://www.novell.com/linux/security/advisories/2010_23_kernel.html -
References () http://www.openwall.com/lists/oss-security/2009/12/04/1 - () http://www.openwall.com/lists/oss-security/2009/12/04/1 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=540736 - () https://bugzilla.redhat.com/show_bug.cgi?id=540736 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10091 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10091 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6750 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6750 -
References () https://rhn.redhat.com/errata/RHSA-2010-0046.html - () https://rhn.redhat.com/errata/RHSA-2010-0046.html -
References () https://rhn.redhat.com/errata/RHSA-2010-0095.html - () https://rhn.redhat.com/errata/RHSA-2010-0095.html -

Information

Published : 2009-12-04 21:30

Updated : 2024-11-21 01:08


NVD link : CVE-2009-4020

Mitre link : CVE-2009-4020

CVE.ORG link : CVE-2009-4020


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer