Release date:
Updated on:
Affected Systems:
Freedesktop udisks
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66081
CVE (CAN) ID: CVE-2014-0004
Udisks and Udisks2 provide a daemon, D-Bus API, and command line tool to manage disks and storage devices.
When udisks and udisks2 process long path names, there is a local stack buffer overflow vulnerability in implementation. Attackers can exploit this vulnerability to execute arbitrary code with root privileges by using a directory structure specially crafted by the plug-in.
<* Source: Florian weian (Weimer@CERT.Uni-Stuttgart.DE)
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 1049703
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Freedesktop
-----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.freedesktop.org/wiki/Software/udisks
Refer:
Http://lists.freedesktop.org/archives/devkit-devel/2014-March/001568.html
Udisks patch:
Http://cgit.freedesktop.org/udisks/commit? H = udisks1 & id = ebf61ed8471
Udisks2 patch:
Http://cgit.freedesktop.org/udisks/commit? Id = 244967