The UDF filesystem implementation in the Linux kernel before 3.18.2 does not validate certain lengths, which allows local users to cause a denial of service (buffer over-read and system crash) via a crafted filesystem image, related to fs/udf/inode.c and fs/udf/symlink.c.
References
Configurations
Information
Published : 2015-08-31 03:59
Updated : 2016-12-21 18:59
NVD link : CVE-2014-9728
Mitre link : CVE-2014-9728
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
linux
- linux_kernel