CVE-2005-2801

xattr.c in the ext2 and ext3 file system code for Linux kernel 2.6 does not properly compare the name_index fields when sharing xattr blocks, which could prevent default ACLs from being applied.
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:*

History

16 Feb 2024, 16:53

Type Values Removed Values Added
References () http://acl.bestbits.at/pipermail/acl-devel/2005-February/001848.html - Exploit () http://acl.bestbits.at/pipermail/acl-devel/2005-February/001848.html - Broken Link, Exploit
References () http://lists.debian.org/debian-kernel/2005/08/msg00238.html - Patch () http://lists.debian.org/debian-kernel/2005/08/msg00238.html - Mailing List, Patch
References () http://secunia.com/advisories/17073 - () http://secunia.com/advisories/17073 - Broken Link
References () http://secunia.com/advisories/17826 - () http://secunia.com/advisories/17826 - Broken Link
References () http://secunia.com/advisories/18056 - () http://secunia.com/advisories/18056 - Broken Link
References () http://secunia.com/advisories/18059 - () http://secunia.com/advisories/18059 - Broken Link
References () http://secunia.com/advisories/19252 - () http://secunia.com/advisories/19252 - Broken Link
References () http://www.debian.org/security/2005/dsa-921 - () http://www.debian.org/security/2005/dsa-921 - Third Party Advisory
References () http://www.debian.org/security/2005/dsa-922 - () http://www.debian.org/security/2005/dsa-922 - Third Party Advisory
References () http://www.mandriva.com/security/advisories?name=MDKSA-2005:219 - () http://www.mandriva.com/security/advisories?name=MDKSA-2005:219 - Broken Link
References () http://www.novell.com/linux/security/advisories/2005_18_kernel.html - Patch, Vendor Advisory () http://www.novell.com/linux/security/advisories/2005_18_kernel.html - Broken Link, Patch, Vendor Advisory
References () http://www.redhat.com/support/errata/RHSA-2005-514.html - () http://www.redhat.com/support/errata/RHSA-2005-514.html - Broken Link
References () http://www.redhat.com/support/errata/RHSA-2006-0144.html - () http://www.redhat.com/support/errata/RHSA-2006-0144.html - Broken Link
References () http://www.securityfocus.com/archive/1/427980/100/0/threaded - () http://www.securityfocus.com/archive/1/427980/100/0/threaded - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/14793 - () http://www.securityfocus.com/bid/14793 - Broken Link, Third Party Advisory, VDB Entry
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10495 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10495 - Broken Link
CWE NVD-CWE-Other CWE-697
CVSS v2 : 5.0
v3 : unknown
v2 : 5.0
v3 : 7.5

Information

Published : 2005-09-06 17:03

Updated : 2024-02-16 16:53


NVD link : CVE-2005-2801

Mitre link : CVE-2005-2801

CVE.ORG link : CVE-2005-2801


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-697

Incorrect Comparison