|
|
Subscribe / Log in / New account

kernel: symlink overflow in the iso9660 filessytem

Package(s):kernel CVE #(s):CAN-2004-0109
Created:April 14, 2004 Updated:July 15, 2004
Description: The 2.4 and 2.6 kernels contain a vulnerability in the iso9660 (CDROM) filesystem which can be used by a local attacker to obtain root privileges. The exploit requires creating a specially-crafted filesystem and getting the kernel to mount it. Many systems are configured to automatically mount CDs on insertion, however, so the possibility of this vulnerability being exploited by users with physical access to the system is real. The 2.4.26 kernel contains the fix, which will also be merged into the upcoming 2.6.6 release.
Alerts:
Conectiva CLA-2004:846 kernel 2004-07-15
Red Hat RHSA-2004:106-01 kernel 2004-04-21
Red Hat RHSA-2004:105-01 kernel 2004-04-21
Debian DSA-489-1 kernel 2004-04-17
Debian DSA-491-1 kernel 2004-04-17
Debian DSA-479-2 kernel-image-2.4.18-1-i386 2004-04-14
SuSE SuSE-SA:2004:009 kernel 2004-04-14
Mandrake MDKSA-2004:029 kernel 2004-04-14
Fedora FEDORA-2004-101 kernel 2004-04-14
Debian DSA-482-1 kernel 2004-04-14
Debian DSA-481-1 kernel 2004-04-14
Debian DSA-480-1 kernel 2004-04-14
Debian DSA-479-1 kernel 2004-04-14

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds