Weekly Vulnerabilities Reports > September 6 to 12, 2010

Overview

7 new vulnerabilities reported during this period, including 0 critical vulnerabilities and 5 high severity vulnerabilities. This weekly summary report vulnerabilities in 18 products from 8 vendors including Linux, Canonical, Suse, Vmware, and Debian. Vulnerabilities are notably categorized as "NULL Pointer Dereference", "Out-of-bounds Write", and "Classic Buffer Overflow".

  • Linux has the most reported vulnerabilities, with 6 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

0 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS

5 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2010-09-08 CVE-2010-2960 Linux
Canonical
Suse
NULL Pointer Dereference vulnerability in multiple products

The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and earlier expects that a certain parent session keyring exists, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a KEYCTL_SESSION_TO_PARENT argument to the keyctl function.

7.8
2010-09-08 CVE-2010-2798 Linux
Vmware
Canonical
Debian
Avaya
Opensuse
Suse
NULL Pointer Dereference vulnerability in multiple products

The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact by renaming a file in a GFS2 filesystem, related to the gfs2_rename function in fs/gfs2/ops_inode.c.

7.8
2010-09-08 CVE-2010-2524 Linux
Vmware
Canonical
Suse
The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a user's keyring for the dns_resolver upcall in the cifs.upcall userspace helper, which allows local users to spoof the results of DNS queries and perform arbitrary CIFS mounts via vectors involving an add_key call, related to a "cache stuffing" issue and MS-DFS referrals.
7.8
2010-09-08 CVE-2010-2492 Linux
Vmware
Avaya
Classic Buffer Overflow vulnerability in multiple products

Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash) via unspecified vectors.

7.8
2010-09-09 CVE-2010-2883 Adobe Out-of-bounds Write vulnerability in Adobe Acrobat and Acrobat Reader

Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010.

7.3

2 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2010-09-08 CVE-2010-2066 Linux
Vmware
Canonical
Suse
The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a MOVE_EXT ioctl call that specifies this file as a donor.
5.5
2010-09-08 CVE-2009-4895 Linux
Debian
Canonical
NULL Pointer Dereference vulnerability in multiple products

Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via unknown vectors, related to the put_tty_queue and __f_setown functions.

4.7

0 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS