Lucene search

K
cve[email protected]CVE-2014-9683
HistoryMar 03, 2015 - 11:59 a.m.

CVE-2014-9683

2015-03-0311:59:02
CWE-189
web.nvd.nist.gov
80
cve-2014-9683
off-by-one error
ecryptfs
ecryptfs subsystem
linux kernel
buffer overflow
denial of service
privilege escalation
nvd

3.6 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

5.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%

Off-by-one error in the ecryptfs_decode_from_filename function in fs/ecryptfs/crypto.c in the eCryptfs subsystem in the Linux kernel before 3.18.2 allows local users to cause a denial of service (buffer overflow and system crash) or possibly gain privileges via a crafted filename.

Affected configurations

NVD
Node
canonicalubuntu_linuxMatch12.04lts
OR
canonicalubuntu_linuxMatch14.04lts
OR
canonicalubuntu_linuxMatch14.10
Node
linuxlinux_kernelRange3.18.1

References

3.6 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

5.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%