CVE-2014-9731

LOW
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The UDF filesystem implementation in the Linux kernel before 3.18.2 does not ensure that space is available for storing a symlink target's name along with a trailing \0 character, which allows local users to obtain sensitive information via a crafted filesystem image, related to fs/udf/symlink.c and fs/udf/unicode.c.

References

http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0e5cc9a40ada6046e6bc3bdfcd0c0d7e4b706b14

http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00023.html

http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00049.html

http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.html

http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.html

http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.html

http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.18.2

http://www.openwall.com/lists/oss-security/2015/06/03/4

http://www.securityfocus.com/bid/75001

https://bugzilla.redhat.com/show_bug.cgi?id=1228220

https://github.com/torvalds/linux/commit/0e5cc9a40ada6046e6bc3bdfcd0c0d7e4b706b14

https://source.android.com/security/bulletin/2017-07-01

Details

Source: MITRE

Published: 2015-08-31

Updated: 2017-07-13

Type: CWE-17

Risk Information

CVSS v2

Base Score: 2.1

Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 3.9

Severity: LOW

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions up to 3.18.1 (inclusive)

Tenable Plugins

View all (8 total)

IDNameProductFamilySeverity
124986EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1533)NessusHuawei Local Security Checks
high
124809EulerOS Virtualization 3.0.1.0 : kernel (EulerOS-SA-2019-1485)NessusHuawei Local Security Checks
high
88545openSUSE Security Update : the Linux Kernel (openSUSE-2016-124)NessusSuSE Local Security Checks
high
86290SUSE SLED11 / SLES11 Security Update : kernel-source (SUSE-SU-2015:1678-1)NessusSuSE Local Security Checks
high
86121SUSE SLED11 / SLES11 Security Update : kernel (SUSE-SU-2015:1611-1)NessusSuSE Local Security Checks
high
85432openSUSE Security Update : the Linux Kernel (openSUSE-2015-543)NessusSuSE Local Security Checks
high
85180SUSE SLED12 / SLES12 Security Update : SUSE Linux Enterprise 12 kernel (SUSE-SU-2015:1324-1)NessusSuSE Local Security Checks
high
84252Debian DLA-246-2 : linux-2.6 regression updateNessusDebian Local Security Checks
high