Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-3528
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-3528

Description:
The error-reporting functionality in (1) fs/ext2/dir.c, (2) fs/ext3/dir.c, and possibly (3) fs/ext4/dir.c in the Linux kernel 2.6.26.5 does not limit the number of printk console messages that report directory corruption, which allows physically proximate attackers to cause a denial of service (temporary system hang) by mounting a filesystem that has corrupted dir->i_size and dir->i_blocks values and performing (a) read or (b) write operations. NOTE: there are limited scenarios in which this crosses privilege boundaries.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/45720

UBUNTU
  http://www.ubuntu.com/usn/usn-662-1

SUSE
  http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00000.html
  http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00001.html
  http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html
  http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00010.html

SAID
  Secunia Advisory: SA32998
  Secunia Advisory: SA33180
  Secunia Advisory: SA32759
  Secunia Advisory: SA32799
  Secunia Advisory: SA32509
  Secunia Advisory: SA32709
  Secunia Advisory: SA33586
  Secunia Advisory: SA33758

REDHAT
  http://www.redhat.com/support/errata/RHSA-2009-0326.html
  http://rhn.redhat.com/errata/RHSA-2008-0972.html
  http://www.redhat.com/support/errata/RHSA-2009-0009.html

MLIST
  http://lkml.org/lkml/2008/9/13/99
  http://lkml.org/lkml/2008/9/17/371
  http://www.openwall.com/lists/oss-security/2008/09/18/2
  http://lkml.org/lkml/2008/9/13/98

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDVSA-2008:224

DEBIAN
  http://www.debian.org/security/2008/dsa-1681
  http://www.debian.org/security/2008/dsa-1687

CONFIRM
  http://wiki.rpath.com/Advisories:rPSA-2008-0316
  http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0316

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/498285/100/0/threaded


Return to the previous page.