CVE-2015-5218 |
|
发布时间 :2015-11-09 11:59:06 | ||
修订时间 :2017-07-19 14:46:48 | ||||
NM |
[原文]Buffer overflow in text-utils/colcrt.c in colcrt in util-linux before 2.27 allows local users to cause a denial of service (crash) via a crafted file, related to the page global variable.
[CNNVD]CNNVD数据暂缺。
[机译]帮助我们改进 Google 翻译
- CVSS (基础分值)
CVSS分值: | 2.1 | [轻微(LOW)] |
机密性影响: | NONE | [对系统的机密性无影响] |
完整性影响: | NONE | [不会对系统完整性产生影响] |
可用性影响: | PARTIAL | [可能会导致性能下降或中断资源访问] |
攻击复杂度: | LOW | [漏洞利用没有访问限制 ] |
攻击向量: | LOCAL | [漏洞利用需要具有物理访问权限或本地帐户] |
身份认证: | NONE | [漏洞利用无需身份认证] |
- CWE (弱点类目)
CWE-119 | [内存缓冲区边界内操作的限制不恰当] |
- CPE (受影响的平台与产品)
cpe:/o:opensuse_project:opensuse:13.2 | |
cpe:/o:opensuse_project:opensuse:13.1 | |
cpe:/o:opensuse_project:leap:42.1 | |
cpe:/a:kernel:util-linux:2.22 |
- OVAL (用于检测的技术细节)
未找到相关OVAL定义 |
- 官方数据库链接
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5218 (官方数据源) MITRE |
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-5218 (官方数据源) NVD |
- 其它链接及资源
http://lists.opensuse.org/opensuse-updates/2015-11/msg00035.html (VENDOR_ADVISORY) SUSE openSUSE-SU-2015:1910 |
http://www.spinics.net/lists/util-linux-ng/msg11873.html (UNKNOWN) MLIST [util-linux] 20150807 crash in colcrt |
https://bugzilla.redhat.com/show_bug.cgi?id=1259322 (VENDOR_ADVISORY) CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=1259322 |
https://github.com/kerolasa/lelux-utiliteetit/commit/70e3fcf293c1827a2655a86584ab13075124a8a8 (VENDOR_ADVISORY) CONFIRM https://github.com/kerolasa/lelux-utiliteetit/commit/70e3fcf293c1827a2655a86584ab13075124a8a8 |
https://github.com/kerolasa/lelux-utiliteetit/commit/d883d64d96ab9bef510745d064a351145b9babec (VENDOR_ADVISORY) CONFIRM https://github.com/kerolasa/lelux-utiliteetit/commit/d883d64d96ab9bef510745d064a351145b9babec |
https://www.kernel.org/pub/linux/utils/util-linux/v2.27/v2.27-ReleaseNotes (VENDOR_ADVISORY) CONFIRM https://www.kernel.org/pub/linux/utils/util-linux/v2.27/v2.27-ReleaseNotes |