CVE-2014-5472

MEDIUM

Description

The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (unkillable mount process) via a crafted iso9660 image with a self-referential CL entry.

References

http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=410dd3cf4c9b36f27ed4542ee18b1af5e68645a4

http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.html

http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.html

http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html

http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html

http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html

http://marc.info/?l=bugtraq&m=142722450701342&w=2

http://marc.info/?l=bugtraq&m=142722544401658&w=2

http://rhn.redhat.com/errata/RHSA-2014-1318.html

http://rhn.redhat.com/errata/RHSA-2015-0102.html

http://rhn.redhat.com/errata/RHSA-2015-0695.html

http://rhn.redhat.com/errata/RHSA-2015-0782.html

http://rhn.redhat.com/errata/RHSA-2015-0803.html

http://www.openwall.com/lists/oss-security/2014/08/27/1

http://www.securityfocus.com/bid/69428

http://www.ubuntu.com/usn/USN-2354-1

http://www.ubuntu.com/usn/USN-2355-1

http://www.ubuntu.com/usn/USN-2356-1

http://www.ubuntu.com/usn/USN-2357-1

http://www.ubuntu.com/usn/USN-2358-1

http://www.ubuntu.com/usn/USN-2359-1

https://bugzilla.redhat.com/show_bug.cgi?id=1134099

https://code.google.com/p/google-security-research/issues/detail?id=88

https://exchange.xforce.ibmcloud.com/vulnerabilities/95556

https://github.com/torvalds/linux/commit/410dd3cf4c9b36f27ed4542ee18b1af5e68645a4

Details

Source: MITRE

Published: 2014-09-01

Updated: 2017-09-08

Type: CWE-20

Risk Information

CVSS v2.0

Base Score: 4

Vector: AV:L/AC:H/Au:N/C:N/I:N/A:C

Impact Score: 6.9

Exploitability Score: 1.9

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:linux:linux_kernel:3.16.0:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions up to 3.16.1 (inclusive)

Tenable Plugins

View all (38 total)

IDNameProductFamilySeverity
124810EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1486)NessusHuawei Local Security Checks
high
124805EulerOS Virtualization 3.0.1.0 : kernel (EulerOS-SA-2019-1481)NessusHuawei Local Security Checks
high
99163OracleVM 3.3 : Unbreakable / etc (OVMSA-2017-0057) (Dirty COW)NessusOracleVM Local Security Checks
critical
85097Oracle Linux 6 : kernel (ELSA-2015-1272)NessusOracle Linux Local Security Checks
high
83723SUSE SLES10 Security Update : kernel (SUSE-SU-2015:0812-1)NessusSuSE Local Security Checks
high
83696SUSE SLES11 Security Update : kernel (SUSE-SU-2015:0481-1)NessusSuSE Local Security Checks
high
82790RHEL 6 : kernel (RHSA-2015:0803)NessusRed Hat Local Security Checks
medium
82691OracleVM 3.3 : kernel-uek (OVMSA-2015-0040)NessusOracleVM Local Security Checks
critical
82636RHEL 6 : kernel (RHSA-2015:0782)NessusRed Hat Local Security Checks
critical
82087Debian DLA-103-1 : linux-2.6 security updateNessusDebian Local Security Checks
medium
81966Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2015-3012)NessusOracle Linux Local Security Checks
high
81906RHEL 6 : kernel (RHSA-2015:0695)NessusRed Hat Local Security Checks
medium
81800Oracle Linux 7 : kernel (ELSA-2015-0290)NessusOracle Linux Local Security Checks
high
81089CentOS 7 : kernel (CESA-2015:0102)NessusCentOS Local Security Checks
high
81073Scientific Linux Security Update : kernel on SL7.x x86_64 (20150128)NessusScientific Linux Local Security Checks
high
81070RHEL 7 : kernel (RHSA-2015:0102)NessusRed Hat Local Security Checks
high
81067Oracle Linux 7 : kernel (ELSA-2015-0102)NessusOracle Linux Local Security Checks
high
80158Oracle Linux 5 / 6 : Unbreakable Enterprise kernel (ELSA-2014-3108)NessusOracle Linux Local Security Checks
high
80157Oracle Linux 5 / 6 : Unbreakable Enterprise kernel (ELSA-2014-3107)NessusOracle Linux Local Security Checks
high
80156Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2014-3106)NessusOracle Linux Local Security Checks
high
80152openSUSE Security Update : the Linux Kernel (openSUSE-SU-2014:1677-1)NessusSuSE Local Security Checks
high
80150openSUSE Security Update : the Linux Kernel (openSUSE-SU-2014:1669-1)NessusSuSE Local Security Checks
high
80099Scientific Linux Security Update : kernel on SL6.x i386/x86_64 (20141216)NessusScientific Linux Local Security Checks
high
80088CentOS 6 : kernel (CESA-2014:1997)NessusCentOS Local Security Checks
high
80072RHEL 6 : kernel (RHSA-2014:1997)NessusRed Hat Local Security Checks
high
80070Oracle Linux 6 : kernel (ELSA-2014-1997)NessusOracle Linux Local Security Checks
high
78651SuSE 11.3 Security Update : Linux kernel (SAT Patch Number 9750)NessusSuSE Local Security Checks
high
78650SuSE 11.3 Security Update : Linux kernel (SAT Patch Numbers 9746 / 9749 / 9751)NessusSuSE Local Security Checks
high
78617Mandriva Linux Security Advisory : kernel (MDVSA-2014:201)NessusMandriva Local Security Checks
high
78006RHEL 6 : MRG (RHSA-2014:1318)NessusRed Hat Local Security Checks
medium
77974Fedora 19 : kernel-3.14.19-100.fc19 (2014-11008)NessusFedora Local Security Checks
medium
77821Ubuntu 14.04 LTS : linux vulnerabilities (USN-2359-1)NessusUbuntu Local Security Checks
high
77820Ubuntu 12.04 LTS : linux-lts-trusty vulnerabilities (USN-2358-1)NessusUbuntu Local Security Checks
high
77819Ubuntu 12.04 LTS : linux vulnerabilities (USN-2356-1)NessusUbuntu Local Security Checks
medium
77818Ubuntu 10.04 LTS : linux-ec2 vulnerabilities (USN-2355-1)NessusUbuntu Local Security Checks
medium
77817Ubuntu 10.04 LTS : linux vulnerabilities (USN-2354-1)NessusUbuntu Local Security Checks
medium
77787Fedora 21 : kernel-3.16.2-300.fc21 (2014-10312)NessusFedora Local Security Checks
medium
77451Fedora 20 : kernel-3.15.10-201.fc20 (2014-9959)NessusFedora Local Security Checks
medium