PT-2009-6764 · Opensuse+3 · Opensuse+3

·

CVE-2009-4020

·

Published

1970-01-01

·

Updated

2023-02-13

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions openSUSE kernel-ps3-debuginfo (affected versions not specified) openSUSE kernel-ps3-debugsource (affected versions not specified) Linux kernel version 2.6.32
Description The issue involves multiple vulnerabilities in the kernel-ps3-debuginfo and kernel-ps3-debugsource packages of the openSUSE operating system, as well as a stack-based buffer overflow in the hfs subsystem of the Linux kernel. These vulnerabilities can be exploited remotely and may lead to a disruption of confidentiality, integrity, and availability of protected information. The buffer overflow is related to the hfs readdir function in fs/hfs/dir.c and can be triggered by a crafted Hierarchical File System (HFS) filesystem.
Recommendations For openSUSE kernel-ps3-debuginfo, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For openSUSE kernel-ps3-debugsource, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Linux kernel version 2.6.32, consider upgrading to a newer version to address the stack-based buffer overflow in the hfs subsystem. As a temporary workaround, consider restricting access to HFS filesystems to minimize the risk of exploitation.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-05250
BDU:2015-05251
CVE-2009-4020
DSA-2003-1
DSA-2005-1
RHSA-2010:0046
RHSA-2010:0076
RHSA-2010_0046
RHSA-2010_0076
SUSE-SU-2012_1056-1
SUSE-SU-2013_1832-1

Affected Products

Linux Kernel
Red Hat
Suse
Opensuse