Vulnerability Name: | CVE-2005-2801 (CCN-21808) | ||||||||||||||||||||||||
Assigned: | 2005-02-05 | ||||||||||||||||||||||||
Published: | 2005-02-05 | ||||||||||||||||||||||||
Updated: | 2018-10-19 | ||||||||||||||||||||||||
Summary: | xattr.c in the ext2 and ext3 file system code for Linux kernel 2.6 does not properly compare the name_index fields when sharing xattr blocks, which could prevent default ACLs from being applied. | ||||||||||||||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||
References: | Source: MLIST Type: Exploit [Acl-Devel] 20050205 [FIX] Long-standing xattr sharing bug Source: MITRE Type: CNA CVE-2005-0757 Source: MITRE Type: CNA CVE-2005-2801 Source: MLIST Type: Patch [debian-kernel] 20050809 Re: ACL patches in Debian 2.4 series kernel. Source: CCN Type: RHSA-2005-294 Updated kernel packages available for Red Hat Enterprise Linux 3 Update 5 Source: CCN Type: RHSA-2005-514 Updated kernel packages available for Red Hat Enterprise Linux 4 Update 2 Source: CCN Type: RHSA-2006-0144 Updated kernel packages available for Red Hat Enterprise Linux 3 Update 7 Source: SECUNIA Type: UNKNOWN 17073 Source: SECUNIA Type: UNKNOWN 17826 Source: SECUNIA Type: UNKNOWN 18056 Source: SECUNIA Type: UNKNOWN 18059 Source: SECUNIA Type: UNKNOWN 19252 Source: DEBIAN Type: UNKNOWN DSA-921 Source: DEBIAN Type: UNKNOWN DSA-922 Source: DEBIAN Type: DSA-921 kernel-source-2.4.27 -- several vulnerabilities Source: DEBIAN Type: DSA-922 kernel-source-2.6.8 -- several vulnerabilities Source: MANDRAKE Type: UNKNOWN MDKSA-2005:219 Source: SUSE Type: Patch, Vendor Advisory SUSE-SA:2005:018 Source: REDHAT Type: UNKNOWN RHSA-2005:514 Source: REDHAT Type: UNKNOWN RHSA-2006:0144 Source: FEDORA Type: UNKNOWN FLSA:157459-3 Source: CCN Type: BID-13680 Linux Kernel 64 Bit EXT3 Filesystem Extended Attribute Denial Of Service Vulnerability Source: BID Type: UNKNOWN 14793 Source: CCN Type: BID-14793 Linux Kernel EXT2/EXT3 File System Access Control Bypass Vulnerability Source: CCN Type: USN-178-1 Linux kernel vulnerabilities Source: XF Type: UNKNOWN redhat-xattr-dos(21808) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10495 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |