Release date:
Updated on:
Affected Systems:
Linux kernel 2.6.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53401
Hierarchical File System (HFS) is a File System developed by Apple.
Linux Kernel (version 3.x <= 3.3.4 and 2.6.x <= 2.6.35.13) contains the HFS + file system driver vulnerability through hfs_bnode_read () (in fs/hfsplus/bnode. c) memcpy () call, the HFS + file system can lead to code execution or permission escalation.
<* Source: Amerigo Wang
Link: http://permalink.gmane.org/gmane.comp.security.oss.general/7610
Http://git.kernel.org /? P = linux/kernel/git/torvalds/linux-2.6.git; a = commitdiff; h = 6f24f892871acc47b40dd594c63606a17c714f77
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kernel.org/