Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-3400

Overview

Vulnerability Score 7.6 7.6
CVE Id CVE-2012-3400
Last Modified 11 May 2015 09:59:37
Published 03 Oct 2012 07:02:56
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity HIGH
Authentication NONE

CVE-2012-3400

Summary

Heap-based buffer overflow in the udf_load_logicalvol function in fs/udf/super.c in the Linux kernel before 3.4.5 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted UDF filesystem.

Vulnerable Systems

Operating System

  • Linux Kernel 3.0

  • Linux Kernel 3.0.1

  • Linux Kernel 3.0.10

  • Linux Kernel 3.0.11

  • Linux Kernel 3.0.12

  • Linux Kernel 3.0.13

  • Linux Kernel 3.0.14

  • Linux Kernel 3.0.15

  • Linux Kernel 3.0.16

  • Linux Kernel 3.0.17

  • Linux Kernel 3.0.18

  • Linux Kernel 3.0.19

  • Linux Kernel 3.0.2

  • Linux Kernel 3.0.20

  • Linux Kernel 3.0.21

  • Linux Kernel 3.0.22

  • Linux Kernel 3.0.23

  • Linux Kernel 3.0.24

  • Linux Kernel 3.0.25

  • Linux Kernel 3.0.26

  • Linux Kernel 3.0.27

  • Linux Kernel 3.0.28

  • Linux Kernel 3.0.29

  • Linux Kernel 3.0.3

  • Linux Kernel 3.0.30

  • Linux Kernel 3.0.31

  • Linux Kernel 3.0.32

  • Linux Kernel 3.0.33

  • Linux Kernel 3.0.34

  • Linux Kernel 3.0.4

  • Linux Kernel 3.0.5

  • Linux Kernel 3.0.6

  • Linux Kernel 3.0.7

  • Linux Kernel 3.0.8

  • Linux Kernel 3.0.9

  • Linux Kernel 3.1

  • Linux Kernel 3.1.1

  • Linux Kernel 3.1.10

  • Linux Kernel 3.1.2

  • Linux Kernel 3.1.3

  • Linux Kernel 3.1.4

  • Linux Kernel 3.1.5

  • Linux Kernel 3.1.6

  • Linux Kernel 3.1.7

  • Linux Kernel 3.1.8

  • Linux Kernel 3.1.9

  • Linux Kernel 3.2

  • Linux Kernel 3.2.1

  • Linux Kernel 3.2.10

  • Linux Kernel 3.2.11

  • Linux Kernel 3.2.12

  • Linux Kernel 3.2.13

  • Linux Kernel 3.2.14

  • Linux Kernel 3.2.15

  • Linux Kernel 3.2.16

  • Linux Kernel 3.2.17

  • Linux Kernel 3.2.18

  • Linux Kernel 3.2.19

  • Linux Kernel 3.2.2

  • Linux Kernel 3.2.20

  • Linux Kernel 3.2.3

  • Linux Kernel 3.2.4

  • Linux Kernel 3.2.5

  • Linux Kernel 3.2.6

  • Linux Kernel 3.2.7

  • Linux Kernel 3.2.8

  • Linux Kernel 3.2.9

  • Linux Kernel 3.3

  • Linux Kernel 3.3.1

  • Linux Kernel 3.3.2

  • Linux Kernel 3.3.3

  • Linux Kernel 3.3.4

  • Linux Kernel 3.3.5

  • Linux Kernel 3.3.6

  • Linux Kernel 3.3.7

  • Linux Kernel 3.3.8

  • Linux Kernel 3.4

  • Linux Kernel 3.4.1

  • Linux Kernel 3.4.2

  • Linux Kernel 3.4.3

  • Linux Kernel 3.4.4


References

CONFIRM - http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=adee11b2085bee90bd8f4f52123ffb07882d6256

CONFIRM - http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=1df2ae31c724e57be9d7ac00d78db8a5dabdd050

CONFIRM - https://github.com/torvalds/linux/commit/adee11b2085bee90bd8f4f52123ffb07882d6256

CONFIRM - https://github.com/torvalds/linux/commit/1df2ae31c724e57be9d7ac00d78db8a5dabdd050

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=843139

MLIST - [oss-security] 20120709 Re: CVE Request: Stability fixes in UDF Logical Volume Descriptor handling

CONFIRM - http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.4.5

UBUNTU - USN-1557-1

UBUNTU - USN-1529-1

SECUNIA - 50506

REDHAT - RHSA-2013:0594

UBUNTU - USN-1556-1

UBUNTU - USN-1555-1

SUSE - SUSE-SU-2015:0812

Related Patches

Novell SUSE 2012:6547 kernel security update for SLE 11 SP1 i586

Novell SUSE 2012:6548 kernel security update for SLE 11 SP1 x86_64

Novell SUSE 2012:6641 kernel security update for SLE 11 SP2 i586

Novell SUSE 2012:6648 kernel security update for SLE 11 SP2 x86_64

Novell SUSE 2012:8324 kernel security update for SLE 10 SP4 x86_64

Novell SUSE 2012:8325 kernel security update for SLE 10 SP4 i586


Last Updated: 27 May 2016 11:00:50