Upstream information
Description
The befs_follow_link function in fs/befs/linuxvfs.c in the Linux kernel before 3.1-rc3 does not validate the length attribute of long symlinks, which allows local users to cause a denial of service (incorrect pointer dereference and OOPS) by accessing a long symlink on a malformed Be filesystem.NVD CVSS v2 Base Score: 4.9 (AV:L/AC:L/Au:N/C:N/I:N/A:C)
Novell/SUSE information
Novell Bugzilla entry: 713430 SUSE Security Advisories:- SUSE-SA:2011:041, published Mon, 17 Oct 2011 16:00:00 +0000
- SUSE-SU-2011:1100-1, published Sat, 8 Oct 2011 01:08:22 +0200 (CEST)
- SUSE-SU-2011:1101-1, published Sat, 8 Oct 2011 01:08:26 +0200 (CEST)
- SUSE-SU-2012:0364-1, published Wed, 14 Mar 2012 00:08:32 +0100 (CET)
- SUSE-SU-2012:0736-1, published Thu, 14 Jun 2012 18:08:31 +0200 (CEST)
- openSUSE-SU-2012:0799-1, published Thu, 28 Jun 2012 10:08:31 +0200 (CEST)
- openSUSE-SU-2012:1439-1, published Mon, 5 Nov 2012 10:09:03 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SLE 11 SERVER Unsupported Extras |
| Builds SAT Patch Nr: 5215 |
| SLE 11 SERVER Unsupported Extras |
| Builds SAT Patch Nr: 5212 |
| SLE 11 SP1 DEBUGINFO |
| sle11-sp1-hae.ia64 sles11-sp1.ia64 SAT Patch Nr: 5220 |
| SUSE Linux Enterprise High Availability Extension 11 SP1 |
| sle11-sp1-hae.ia64 sles11-sp1.ia64 SAT Patch Nr: 5220 |
| SUSE Linux Enterprise Server 11 SP1 |
| sle11-sp1-hae.ia64 sles11-sp1.ia64 SAT Patch Nr: 5220 |
| SUSE Linux Enterprise Real Time 11 SP1 |
| slert11-sp1.x86-64 SAT Patch Nr: 5802 |
| SLE 11 SP1 DEBUGINFO |
| sles11-sp1.x86 sled11-sp1.x86 sles11-sp1-vmware.x86 sle11-sp1-hae.x86 SAT Patch Nr: 5219 |
| SUSE Linux Enterprise High Availability Extension 11 SP1 |
| sles11-sp1.x86 sled11-sp1.x86 sles11-sp1-vmware.x86 sle11-sp1-hae.x86 SAT Patch Nr: 5219 |
| SUSE Linux Enterprise Desktop 11 SP1 |
| sles11-sp1.x86 sled11-sp1.x86 sles11-sp1-vmware.x86 sle11-sp1-hae.x86 SAT Patch Nr: 5219 |
| SUSE Linux Enterprise Server 11 SP1 for VMware |
| sles11-sp1.x86 sled11-sp1.x86 sles11-sp1-vmware.x86 sle11-sp1-hae.x86 SAT Patch Nr: 5219 |
| SUSE Linux Enterprise Server 11 SP1 |
| sles11-sp1.x86 sled11-sp1.x86 sles11-sp1-vmware.x86 sle11-sp1-hae.x86 SAT Patch Nr: 5219 |
| SUSE Linux Enterprise 10 SP4 DEBUGINFO for IPF |
| Builds ZYPP Patch Nr: 8160 |
| SLE SDK 10 SP4 for IPF |
| Builds ZYPP Patch Nr: 8160 |
| SUSE Linux Enterprise Server 10 SP4 for IPF |
| Builds ZYPP Patch Nr: 8160 |
| SLE 11 SP1 DEBUGINFO |
| sle11-sp1-hae.s390x sles11-sp1.s390x SAT Patch Nr: 5222 |
| SUSE Linux Enterprise High Availability Extension 11 SP1 |
| sle11-sp1-hae.s390x sles11-sp1.s390x SAT Patch Nr: 5222 |
| SUSE Linux Enterprise Server 11 SP1 |
| sle11-sp1-hae.s390x sles11-sp1.s390x SAT Patch Nr: 5222 |
| SLE 11 SP1 DEBUGINFO |
| sles11-sp1-vmware.x86-64 sled11-sp1.x86-64 SAT Patch Nr: 5223 |
| SUSE Linux Enterprise High Availability Extension 11 SP1 |
| sles11-sp1-vmware.x86-64 sled11-sp1.x86-64 SAT Patch Nr: 5223 |
| SUSE Linux Enterprise Desktop 11 SP1 |
| sles11-sp1-vmware.x86-64 sled11-sp1.x86-64 SAT Patch Nr: 5223 |
| SUSE Linux Enterprise Server 11 SP1 for VMware |
| sles11-sp1-vmware.x86-64 sled11-sp1.x86-64 SAT Patch Nr: 5223 |
| SUSE Linux Enterprise Server 11 SP1 |
| sles11-sp1-vmware.x86-64 sled11-sp1.x86-64 SAT Patch Nr: 5223 |
| SUSE Linux Enterprise Desktop 10 SP4 for AMD64 and Intel EM64T |
| Builds ZYPP Patch Nr: 8161 |
| SUSE Linux Enterprise 10 SP4 DEBUGINFO for AMD64 and Intel EM64T |
| Builds ZYPP Patch Nr: 8161 |
| SLE SDK 10 SP4 for X86-64 |
| Builds ZYPP Patch Nr: 8161 |
| SUSE Linux Enterprise Server 10 SP4 for AMD64 and Intel EM64T |
| Builds ZYPP Patch Nr: 8161 |
| SLE 11 SP1 DEBUGINFO |
| sle11-sp1-hae.ppc sles11-sp1.ppc SAT Patch Nr: 5221 |
| SUSE Linux Enterprise High Availability Extension 11 SP1 |
| sle11-sp1-hae.ppc sles11-sp1.ppc SAT Patch Nr: 5221 |
| SUSE Linux Enterprise Server 11 SP1 |
| sle11-sp1-hae.ppc sles11-sp1.ppc SAT Patch Nr: 5221 |
| SUSE CORE 9 for AMD64 and Intel EM64T |
| Builds YOU Patch Nr: 12854 |
| SUSE Linux Enterprise 10 SP4 DEBUGINFO for IBM POWER |
| Builds ZYPP Patch Nr: 8163 |
| SLE SDK 10 SP4 for IBM iSeries and IBM pSeries |
| Builds ZYPP Patch Nr: 8163 |
| SUSE Linux Enterprise Server 10 SP4 for IBM POWER |
| Builds ZYPP Patch Nr: 8163 |
| SLE 11 SERVER Unsupported Extras |
| Builds SAT Patch Nr: 5213 |
| SLE 11 SERVER Unsupported Extras |
| Builds SAT Patch Nr: 5214 |
| SLE 11 SERVER Unsupported Extras |
| Builds SAT Patch Nr: 5216 |
