Weekly Vulnerabilities Reports > May 14 to 20, 2012

Overview

13 new vulnerabilities reported during this period, including 0 critical vulnerabilities and 3 high severity vulnerabilities. This weekly summary report vulnerabilities in 16 products from 7 vendors including Linux, Redhat, Suse, Canonical, and Debian. Vulnerabilities are notably categorized as "NULL Pointer Dereference", "Integer Overflow or Wraparound", "Resource Exhaustion", "Infinite Loop", and "Improper Input Validation".

  • 1 reported vulnerabilities are remotely exploitables.
  • 1 reported vulnerabilities are exploitable by an anonymous user.
  • Linux has the most reported vulnerabilities, with 13 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

0 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS

3 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2012-05-17 CVE-2012-1097 Linux
Redhat
Suse
NULL Pointer Dereference vulnerability in multiple products

The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a (1) PTRACE_GETREGSET or (2) PTRACE_SETREGSET ptrace call.

7.8
2012-05-17 CVE-2012-0044 Linux
Canonical
Integer Overflow or Wraparound vulnerability in multiple products

Integer overflow in the drm_mode_dirtyfb_ioctl function in drivers/gpu/drm/drm_crtc.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 3.1.5 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted ioctl call.

7.8
2012-05-17 CVE-2012-0207 Linux
Redhat
Divide By Zero vulnerability in multiple products

The igmp_heard_query function in net/ipv4/igmp.c in the Linux kernel before 3.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and panic) via IGMP packets.

7.5

10 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2012-05-17 CVE-2012-1146 Linux
Fedoraproject
Suse
NULL Pointer Dereference vulnerability in multiple products

The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly handle multiple events that are attached to the same eventfd, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by registering memory threshold events.

5.5
2012-05-17 CVE-2012-1090 Linux
Redhat
Suse
Improper Input Validation vulnerability in multiple products

The cifs_lookup function in fs/cifs/dir.c in the Linux kernel before 3.2.10 allows local users to cause a denial of service (OOPS) via attempted access to a special file, as demonstrated by a FIFO.

5.5
2012-05-17 CVE-2012-0879 Linux
Canonical
Debian
Suse
Resource Exhaustion vulnerability in multiple products

The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a denial of service (I/O instability) by starting multiple processes that share an I/O context.

5.5
2012-05-17 CVE-2012-0058 Linux Resource Exhaustion vulnerability in Linux Kernel

The kiocb_batch_free function in fs/aio.c in the Linux kernel before 3.2.2 allows local users to cause a denial of service (OOPS) via vectors that trigger incorrect iocb management.

5.5
2012-05-17 CVE-2012-0038 Linux Integer Overflow or Wraparound vulnerability in Linux Kernel

Integer overflow in the xfs_acl_from_disk function in fs/xfs/xfs_acl.c in the Linux kernel before 3.1.9 allows local users to cause a denial of service (panic) via a filesystem with a malformed ACL, leading to a heap-based buffer overflow.

5.5
2012-05-17 CVE-2011-4621 Linux Infinite Loop vulnerability in Linux Kernel

The Linux kernel before 2.6.37 does not properly implement a certain clock-update optimization, which allows local users to cause a denial of service (system hang) via an application that executes code in a loop.

5.5
2012-05-17 CVE-2011-4594 Linux NULL Pointer Dereference vulnerability in Linux Kernel

The __sys_sendmsg function in net/socket.c in the Linux kernel before 3.1 allows local users to cause a denial of service (system crash) via crafted use of the sendmmsg system call, leading to an incorrect pointer dereference.

5.5
2012-05-17 CVE-2011-4112 Linux
Avaya
The net subsystem in the Linux kernel before 3.1 does not properly restrict use of the IFF_TX_SKB_SHARING flag, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability to access /proc/net/pktgen/pgctrl, and then using the pktgen package in conjunction with a bridge device for a VLAN interface.
5.5
2012-05-17 CVE-2011-4097 Linux
Redhat
Integer Overflow or Wraparound vulnerability in multiple products

Integer overflow in the oom_badness function in mm/oom_kill.c in the Linux kernel before 3.1.8 on 64-bit platforms allows local users to cause a denial of service (memory consumption or process termination) by using a certain large amount of memory.

5.5
2012-05-17 CVE-2011-3637 Linux
Redhat
NULL Pointer Dereference vulnerability in multiple products

The m_stop function in fs/proc/task_mmu.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (OOPS) via vectors that trigger an m_start error.

5.5

0 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS