Linux kernel ISO9660 filesystem buffer overflow

linux-iso9660-bo (15866) The risk level is classified as HighHigh Risk

Description:

Linux kernel is vulnerable to a buffer overflow, caused by a vulnerability in the ISO9660 filesystem. A local attacker could exploit this vulnerability to overflow a buffer and gain unauthorized root access to the system.


Consequences:

Gain Access

Remedy:

Upgrade to the latest version of Linux kernel (2.4.26-rc4 or later), available from the Linux kernel Web site. See References.

For Debian GNU/Linux 3.0 (woody):
Upgrade to the latest version of kernel (2.4.19-4.woody2 or later), as listed in DSA 491-1. See References.

For Debian GNU/Linux 3.0 (woody) containing the arm-2.4.16 package:
Upgrade to the latest arm-2.4.16 package (2.4.16 or later), as listed in DSA-495-1. See References.

For Mandrake Linux:
Upgrade to the latest kernel package, as listed below. Refer to MandrakeSoft Security Advisory MDKSA-2004:029 : kernel for more information. See References.

Mandrake Linux 9.1: 2.4.21.0.29mdk-1-1mdk or later
Mandrake Linux 9.2: 2.4.22.29mdk-1-1mdk or later
Mandrake Linux Multi Network Firewall 8.2: 2.4.19.39mdk-1-1mdk or later
Mandrake Linux Corporate Server 2.1: 2.4.19.39mdk-1-1mdk or later
Mandrake Linux 10.0: 2.4.25.3mdk-1-1mdk or later

For Trustix Secure Linux 2, 2.0, and 2.1:
Upgrade to the latest kernel package (2.4.25-6tr or later), as listed in Trustix Secure Linux Security Advisory #2004-0020. See References.

For Red Hat Linux 9:
Upgrade to the latest version of kernel (2.4.20-31.9 or later), as listed in RHSA-2004:166-08. See References.

For Red Hat Linux:
Upgrade to the latest kernel package, as listed below. Refer to RHSA-2004:105-13 for more information. See References.

Red Hat Enterprise Linux AS (v. 2.1), ES (v. 2.1), and WS (v. 2.1): 2.4.9-e.40 or later

For Red Hat Linux:
Upgrade to the latest kernel package, as listed below. Refer to RHSA-2004:106-10 for more information. See References.

Red Hat Enterprise Linux AS (v. 2.1) and Advanced Workstation 2.1 for the Itanium Processor: 2.4.18-e.43 or later

For Red Hat Linux:
Upgrade to the latest kernel package, as listed below. Refer to RHSA-2004:183-03 for more information. See References.

Red Hat Enterprise Linux AS (v. 3), ES (v. 3), and WS (v. 3): 2.4.21-9.0.3 or later

For EnGarde Secure Linux Community Edition and Professional Edition:
Apply the update for this vulnerability, as listed in Guardian Digital Security Advisory ESA-20040428-004. See References.

For Turbolinux:
Upgrade to the latest kernel package, as listed below. Refer to Turbolinux Security Advisory TLSA-2004-14 for more information. See References.

Turbolinux Appliance Server 1.0 Hosting Edition: 2.4.25-3 or later
Turbolinux 10 Desktop: 2.6.0-8 or later
Turbolinux 8 Server or Workstation: 2.4.18-19 or later
Turbolinux 7 Server or Workstation: 2.4.18-19 or later

For Gentoo Linux:
Upgrade to the latest version of kernel, as listed in GLSA 200407-02. See References.

For Conectiva Linux:
Upgrade to the latest kernel package, as listed below. Refer to Conectiva Linux Security Announcement CLSA-2004:846 for more information. See References.

Conectiva Linux 8: 2.4.19-1U80_24cl or later
Conectiva Linux 9: 2.4.21-31301U90_18cl or later

For other distributions:
Contact your vendor for upgrade or patch information.

References:

  • CIAC Information Bulletin 0-127: Linux kernel Vulnerabilities.
  • CIAC Information Bulletin O-121: Debian linux-kernel-2.4.17 and 2.4.18 Vulnerabilities.
  • CIAC Information Bulletin O-126: Red Hat Updated Kernel Packages Fix Several ulnerabilities.
  • Conectiva Linux Announcement CLSA-2004:846: Fixes for kernel vulnerabilities.
  • DSA 479-1: New Linux 2.4.18 packages fix local root exploit (source+alpha+i386+powerpc.
  • DSA 480-1: New Linux 2.4.17 and 2.4.18 packages fix local root exploit (hppa).
  • DSA 481-1: linux-kernel-2.4.17-ia64 -- several vulnerabilities.
  • DSA 482-1: New Linux 2.4.17 packages fix local root exploit (source+powerpc/apus+s390).
  • DSA 491-1: linux-kernel-2.4.19-mips -- several vulnerabilities.
  • Guardian Digital Security Advisory ESA-20040428-004: kernel.
  • Linux kernel Web site: The Linux Kernel Archives.
  • Trustix Secure Linux Security Advisory #2004-0020: kernel. (From LinuxSecurity archive)
  • BID-10141: Linux Kernel ISO9660 File System Buffer Overflow Vulnerability
  • CVE-2004-0109: Buffer overflow in the ISO9660 file system component for Linux kernel 2.4.x, 2.5.x and 2.6.x, allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry.
  • DSA-479: linux-kernel-2.4.18-alpha+i386+powerpc -- several vulnerabilities
  • DSA-480: linux-kernel-2.4.17+2.4.18-hppa -- several vulnerabilities
  • DSA-481: linux-kernel-2.4.17-ia64 -- several vulnerabilities
  • DSA-482: linux-kernel-2.4.17-apus+s390 -- several vulnerabilities
  • DSA-489: linux-kernel-2.4.17-mips+mipsel -- several vulnerabilities
  • DSA-491: linux-kernel-2.4.19-mips -- several vulnerabilities
  • DSA-495: linux-kernel-2.4.16-arm -- several vulnerabilities
  • GLSA-200407-02: Linux Kernel: Multiple vulnerabilities
  • MDKSA-2004:029: Updated kernel packages fix multiple vulnerabilities
  • RHSA-2004-105: kernel security update
  • RHSA-2004-106: kernel security update
  • RHSA-2004-166: Updated kernel packages resolve security vulnerabilities
  • RHSA-2004-183: kernel security update
  • SA11361: Linux Kernel ISO9660 Buffer Overflow Privilege Escalation Vulnerability
  • SA11362: Linux Kernel File Systems Information Leak and Denial of Service
  • SA11429: Linux Kernel setsockopt MCAST_MSFILTER Integer Overflow Vulnerability
  • SA11464: Linux Kernel CPUFREQ Proc Handler Kernel Memory Disclosure Vulnerability
  • SA11486: Linux Kernel Framebuffer Driver Direct Userspace Access Vulnerability
  • SA11518: PaX Denial of Service Vulnerability
  • SA11626: Linux Kernel e1000 Network Driver Kernel Memory Disclosure
  • SA11861: Linux Kernel "__clear_fpu()" Macro Denial of Service Vulnerability
  • SA11891: Linux Kernel Various Drivers Userland Pointer Dereference Vulnerabilities
  • SA11986: RSBAC Privilege Escalation Vulnerabilities
  • SUSE-SA:2004:009: Linux Kernel: local privilege escalation / information leakage

Platforms Affected:

  • Conectiva Linux 8.0
  • Conectiva Linux 9.0
  • Debian Debian Linux 3.0
  • EngardeLinux Secure Community 2.0
  • EngardeLinux Secure Professional 1.5
  • Gentoo Linux
  • Linux Kernel 2.4.0 test12
  • Linux Kernel 2.4.0 test2
  • Linux Kernel 2.4.0 test3
  • Linux Kernel 2.4.0 test4
  • Linux Kernel 2.4.0 test5
  • Linux Kernel 2.4.0 test6
  • Linux Kernel 2.4.0 test7
  • Linux Kernel 2.4.0 test8
  • Linux Kernel 2.4.0 test9
  • Linux Kernel 2.4.0 test1
  • Linux Kernel 2.4.0 test10
  • Linux Kernel 2.4.0 test11
  • Linux Kernel 2.4.1
  • Linux Kernel 2.4.10
  • Linux Kernel 2.4.11
  • Linux Kernel 2.4.12
  • Linux Kernel 2.4.13
  • Linux Kernel 2.4.14
  • Linux Kernel 2.4.15
  • Linux Kernel 2.4.16
  • Linux Kernel 2.4.17
  • Linux Kernel 2.4.18 pre1
  • Linux Kernel 2.4.18 pre2
  • Linux Kernel 2.4.18 pre3
  • Linux Kernel 2.4.18 pre4
  • Linux Kernel 2.4.18 x86
  • Linux Kernel 2.4.18
  • Linux Kernel 2.4.18 pre5
  • Linux Kernel 2.4.18 pre6
  • Linux Kernel 2.4.18 pre7
  • Linux Kernel 2.4.18 pre8
  • Linux Kernel 2.4.19 pre2
  • Linux Kernel 2.4.19 pre3
  • Linux Kernel 2.4.19 pre4
  • Linux Kernel 2.4.19 pre1
  • Linux Kernel 2.4.19 pre5
  • Linux Kernel 2.4.19
  • Linux Kernel 2.4.19 pre6
  • Linux Kernel 2.4.2
  • Linux Kernel 2.4.20
  • Linux Kernel 2.4.21
  • Linux Kernel 2.4.21 pre1
  • Linux Kernel 2.4.21 pre4
  • Linux Kernel 2.4.21 pre7
  • Linux Kernel 2.4.22
  • Linux Kernel 2.4.23
  • Linux Kernel 2.4.23 pre9
  • Linux Kernel 2.4.24 ow1
  • Linux Kernel 2.4.24
  • Linux Kernel 2.4.25
  • Linux Kernel 2.4.3
  • Linux Kernel 2.4.4
  • Linux Kernel 2.4.5
  • Linux Kernel 2.4.6
  • Linux Kernel 2.4.7
  • Linux Kernel 2.4.8
  • Linux Kernel 2.4.9
  • Linux Kernel 2.5.0
  • Linux Kernel 2.6.0
  • MandrakeSoft Mandrake Linux 10.0
  • MandrakeSoft Mandrake Linux 9.1
  • MandrakeSoft Mandrake Linux 9.1 PPC
  • MandrakeSoft Mandrake Linux 9.2
  • MandrakeSoft Mandrake Linux 9.2 AMD64
  • MandrakeSoft Mandrake Linux Corporate Server 2.1
  • MandrakeSoft Mandrake Linux Corporate Server 2.1 X86_64
  • MandrakeSoft Mandrake Multi Network Firewall 8.2
  • Novell SuSE Linux Enterprise Server 7.0
  • RedHat Enterprise Linux 2.1 AS
  • RedHat Enterprise Linux 2.1 ES
  • RedHat Enterprise Linux 2.1 WS
  • RedHat Enterprise Linux 2.1 AW
  • RedHat Enterprise Linux 3 AS
  • RedHat Enterprise Linux 3 WS
  • RedHat Enterprise Linux 3 ES
  • RedHat Linux 9.0
  • RedHat Linux Advanced Workstation 2.1 Itanium
  • SUSE SuSE Linux 8.1
  • SUSE SuSE Linux 9.0
  • SuSE SuSE Linux Connectivity Server
  • SuSE SuSE Linux Database Server
  • SuSE SuSE Linux Office Server
  • Trustix Secure Enterprise Linux 2.0
  • Trustix Secure Linux 2.0
  • Trustix Secure Linux 2.1
  • Turbolinux Turbolinux 10 Desktop
  • Turbolinux Turbolinux 7 Server
  • Turbolinux Turbolinux 7 Workstation
  • Turbolinux Turbolinux 8 Server
  • Turbolinux Turbolinux 8 Workstation
  • Turbolinux Turbolinux Appliance Server 1.0
  • Turbolinux Turbolinux Appliance Server 1.0 Hosting Ed
  • Turbolinux Turbolinux Appliance Server 1.0 Workgroup Ed

Reported:

Apr 14, 2004

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page