CVE-2011-4330: Buffer Overflow
Last updated 24 July 2024
Other sources
On a corrupted file system the ->len field could be wrong leading to a buffer overflow.
https://lkml.org/lkml/2011/11/9/303
Upstream commit: http://git.kernel.org/linus/bc5b8a9003132ae44559edd63a1623
Acknowledgements:
Red Hat would like to thank Clement Lecigne for reporting this issue.
— Red Hat
Stack-based buffer overflow in the hfsmac2asc function in fs/hfs/trans.c in the Linux kernel 2.6 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via an HFS image with a crafted len field.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4330?
CVE-2011-4330 has a high severity level due to its potential to cause buffer overflow, which can lead to arbitrary code execution.
How do I fix CVE-2011-4330?
To fix CVE-2011-4330, you should update your Linux kernel to a version later than 3.0.10 or to a version before 3.1.2.
What systems are affected by CVE-2011-4330?
CVE-2011-4330 affects various versions of the Linux kernel, specifically those in the 2.6 and 3.0.x series.
What type of vulnerability is CVE-2011-4330?
CVE-2011-4330 is a buffer overflow vulnerability caused by incorrect handling of the '->len' field on corrupted file systems.
Is CVE-2011-4330 present in all Linux kernel versions?
No, CVE-2011-4330 is not present in all Linux kernel versions; it specifically affects versions up to 3.0.10 and those from 3.1 to 3.1.2.