CVE-2014-9683: Buffer Overflow
A buffer overflow flaw was found in the way the Linux kernel's eCryptfs implementation decoded encrypted file names. A local, unprivileged user could use this flaw to crash the system or, potentially, escalate their privileges on the system.
Upstream fix: ------------- -> https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=942080643bce061c3dd9d5718d3b745dcb39a8bc
Reference: ----------- -> http://seclists.org/oss-sec/2015/q1/582
Other sources
Off-by-one error in the ecryptfsdecodefromfilename function in fs/ecryptfs/crypto.c in the eCryptfs subsystem in the Linux kernel before 3.18.2 allows local users to cause a denial of service (buffer overflow and system crash) or possibly gain privileges via a crafted filename.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9683?
CVE-2014-9683 is considered a high severity vulnerability due to its potential to cause system crashes and privilege escalation.
How do I fix CVE-2014-9683?
To fix CVE-2014-9683, upgrade to the patched versions of the Linux kernel that include the appropriate security updates.
Who is affected by CVE-2014-9683?
CVE-2014-9683 affects local, unprivileged users on systems running vulnerable versions of the Linux kernel, particularly under Ubuntu and Debian.
What impact does CVE-2014-9683 have?
The impact of CVE-2014-9683 includes potential system crashes and the ability for exploited users to escalate their privileges.
Is there a specific Linux kernel version that addresses CVE-2014-9683?
Yes, versions of the Linux kernel post 3.18.1 and specific patched Debian package versions address CVE-2014-9683.