UBUNTU-CVE-2011-2182
Dashboard / Vulnerabilities / UBUNTU-CVE-2011-2182
UBUNTU-CVE-2011-2182
Summary:
Details: The ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel before 2.6.39.1 does not properly handle memory allocation for non-initial fragments, which might allow local users to conduct buffer overflow attacks, and gain privileges or obtain sensitive information, via a crafted LDM partition table. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1017.
References: https://ubuntu.com/security/CVE-2011-2182, http://lkml.org/lkml/2011/5/6/407, http://lkml.org/lkml/2011/6/1/119, http://openwall.com/lists/oss-security/2011/02/23/16, https://ubuntu.com/security/notices/USN-1341-1, https://ubuntu.com/security/notices/USN-1203-1, https://ubuntu.com/security/notices/USN-1208-1, https://ubuntu.com/security/notices/USN-1193-1, https://ubuntu.com/security/notices/USN-1218-1, https://ubuntu.com/security/notices/USN-1216-1, https://ubuntu.com/security/notices/USN-1383-1, https://ubuntu.com/security/notices/USN-1390-1, https://ubuntu.com/security/notices/USN-1392-1, https://ubuntu.com/security/notices/USN-1394-1, https://ubuntu.com/security/notices/USN-1256-1, https://ubuntu.com/security/notices/USN-1332-1, https://www.cve.org/CVERecord?id=CVE-2011-2182
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
