CVE-2010-2943
28Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendepss 17%
de la publicación al arma0 días
Publicada en NVD30 sept
1ª PoC29 sept
probabilidad de explotación
17%top 3% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked file, by accessing a stale NFS filehandle.
Productos afectados
n/a · n/aPoCs públicas encontradas — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/15155⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
http://article.gmane.org/gmane.comp.file-systems.xfs.general/33767http://article.gmane.org/gmane.comp.file-systems.xfs.general/33768http://article.gmane.org/gmane.comp.file-systems.xfs.general/33769http://article.gmane.org/gmane.comp.file-systems.xfs.general/33771http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1920779e67cbf5ea8afef317777c5bf2b8096188http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7124fe0a5b619d65b739477b3b55a20bf805b06dhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7b6259e7a83647948fa33a736cc832310c8d85aahttp://oss.sgi.com/archives/xfs/2010-06/msg00191.htmlhttp://oss.sgi.com/archives/xfs/2010-06/msg00198.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=624923http://secunia.com/advisories/42758http://secunia.com/advisories/43161