CVE-2006-5757
Vulnerability Summary
Timeline
Description
Race condition in the __find_get_block_slow function in the ISO9660 filesystem in Linux 2.6.18 and possibly other versions allows local users to cause a denial of service (infinite loop) by mounting a crafted ISO9660 filesystem containing malformed data structures.
CVSS Metrics
- v2.0•LOW•Score: 1.2AV:L/AC:H/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 1.40%• Percentile: 81%
Techniques & Countermeasures
- CWE-17•DEPRECATED: Code
This entry has been deprecated. It was originally used for organizing the Development View (CWE-699) and some other views, but it introduced unnecessary complexity and depth to the resulting tree.
- CWE-399•Resource Management Errors
Weaknesses in this category are related to improper management of system resources.
Affected Systems
- linux•linux_kernel
2.6.0:test1 | 2.6.0:test10 | 2.6.0:test11 | 2.6.0:test2 | 2.6.0:test3 | 2.6.0:test4 | 2.6.0:test5 | 2.6.0:test6 | 2.6.0:test7 | 2.6.0:test8 | 2.6.0:test9 | 2.6.1 | 2.6.1:rc1 | 2.6.1:rc2 | 2.6.2 | 2.6.3 | 2.6.4 | 2.6.5 | 2.6.6 | 2.6.6:rc1 | 2.6.7 | 2.6.7:rc1 | 2.6.8 | 2.6.8:rc1 | 2.6.8:rc2 | 2.6.8:rc3 | 2.6.9:2.6.20 | 2.6.10 | 2.6.10:rc2 | 2.6.11 | 2.6.11:rc2 | 2.6.11:rc3 | 2.6.11:rc4 | 2.6.11.4 | 2.6.11.5 | 2.6.11.6 | 2.6.11.7 | 2.6.11.8 | 2.6.11.11 | 2.6.11.12 | 2.6.12 | 2.6.12:rc1 | 2.6.12:rc4 | 2.6.12:rc5 | 2.6.12.1 | 2.6.12.2 | 2.6.12.3 | 2.6.12.4 | 2.6.12.5 | 2.6.12.6 | 2.6.13 | 2.6.13:rc1 | 2.6.13:rc4 | 2.6.13:rc6 | 2.6.13:rc7 | 2.6.13.1 | 2.6.13.2 | 2.6.13.3 | 2.6.13.4 | 2.6.14 | 2.6.14:rc1 | 2.6.14:rc2 | 2.6.14:rc3 | 2.6.14:rc4 | 2.6.14.1 | 2.6.14.2 | 2.6.14.3 | 2.6.14.4 | 2.6.14.5 | 2.6.15 | 2.6.15:rc1 | 2.6.15:rc3 | 2.6.15.1 | 2.6.15.2 | 2.6.15.3 | 2.6.15.4 | 2.6.15.5 | 2.6.16 | 2.6.16:rc1 | 2.6.16.1 | 2.6.16.7 | 2.6.16.9 | 2.6.16.11 | 2.6.16.12 | 2.6.16.13 | 2.6.16.19 | 2.6.16.23 | 2.6.16.27 | 2.6.17 | 2.6.17:rc5 | 2.6.17.1 | 2.6.17.3 | 2.6.17.5 | 2.6.17.6 | 2.6.17.7 | 2.6.17.8 | 2.6.17.10 | 2.6.17.11 | 2.6.17.12 | 2.6.17.13 | 2.6.17.14 | 2.6.18 | 2.6.18.1 | 2.6.19:rc1 | 2.6_test9_cvs
References (23)
- http://secunia.com/advisories/24098
- http://www.novell.com/linux/security/advisories/2006_79_kernel.html
- http://www.securityfocus.com/bid/20920
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30029
- http://www.vupen.com/english/advisories/2006/4359
- http://rhn.redhat.com/errata/RHSA-2007-0014.html
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:012
- http://secunia.com/advisories/23593
- http://support.avaya.com/elmodocs2/security/ASA-2007-063.htm
- http://www.ubuntu.com/usn/usn-416-1
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10111
- http://secunia.com/advisories/23752
- http://secunia.com/advisories/24206
- http://secunia.com/advisories/23474
- http://secunia.com/advisories/22746
- http://secunia.com/advisories/23997
- http://www.securityfocus.com/archive/1/471457
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:002
- http://www.debian.org/security/2007/dsa-1304
- http://secunia.com/advisories/25714
- http://secunia.com/advisories/25691
- http://secunia.com/advisories/22702
- http://projects.info-pull.com/mokb/MOKB-05-11-2006.html