CVE-2014-9731
SUSE Security Advisory - SUSE-SU-2015:1611-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The UDF filesystem implementation in the Linux kernel before 3.18.2 does not ensure that space is available for storing a symlink target's name along with a trailing \0 character, which allows local users to obtain sensitive information via a crafted filesystem image, related to fs/udf/symlink.c and fs/udf/unicode.c.
Vulnerabilidad en la implementación del sistema de archivos UDF en el kernel de Linux en versiones anteriores a 3.18.2, no asegura que haya espacio disponible para almacenar el nombre de destino de un link simbólico junto con el carácter \0 al final, lo que permite a usuarios locales obtener información sensible a través de una imagen de sistema de archivos manipulados, relacionado con fs/udf/symlink.c y fs/udf/unicode.c.
An update that solves 14 vulnerabilities and has 45 fixes is now available. The SUSE Linux Enterprise 11 SP3 kernel was updated to receive various security and bug fixes.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-06-03 CVE Reserved
- 2015-08-31 CVE Published
- 2024-08-06 CVE Updated
- 2025-05-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-17: DEPRECATED: Code
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0e5cc9a40ada6046e6bc3bdfcd0c0d7e4b706b14 | X_refsource_confirm | |
http://www.openwall.com/lists/oss-security/2015/06/03/4 | Mailing List |
|
http://www.securityfocus.com/bid/75001 | Vdb Entry | |
https://bugzilla.redhat.com/show_bug.cgi?id=1228220 | X_refsource_confirm | |
https://github.com/torvalds/linux/commit/0e5cc9a40ada6046e6bc3bdfcd0c0d7e4b706b14 | X_refsource_confirm | |
https://source.android.com/security/bulletin/2017-07-01 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | <= 3.18.1 Search vendor "Linux" for product "Linux Kernel" and version " <= 3.18.1" | - |
Affected
|