CVE-2009-1633: Buffer Overflow
Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malformed Unicode string, related to Unicode string area alignment in fs/cifs/sess.c; or (2) long Unicode characters, related to fs/cifs/cifssmb.c and the cifsreaddir function in fs/cifs/readdir.c.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1633?
CVE-2009-1633 is considered a moderate severity vulnerability that can lead to denial of service due to memory corruption.
How do I fix CVE-2009-1633?
To fix CVE-2009-1633, upgrade the Linux kernel to version 2.6.29.4 or later.
What systems are affected by CVE-2009-1633?
CVE-2009-1633 affects various Linux distributions including Debian 4.0, 5.0 and Ubuntu 6.06, 8.04, 8.10, and 9.04.
What type of vulnerability is CVE-2009-1633?
CVE-2009-1633 is a buffer overflow vulnerability in the CIFS subsystem of the Linux kernel.
Can CVE-2009-1633 lead to data loss?
While CVE-2009-1633 primarily causes denial of service, it may indirectly lead to data loss due to memory corruption.