PublicDateAtUSN: 2009-12-04 Candidate: CVE-2009-4020 PublicDate: 2009-12-04 21:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4020 https://ubuntu.com/security/notices/USN-894-1 Description: Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical File System (HFS) filesystem, related to the hfs_readdir function in fs/hfs/dir.c. Ubuntu-Description: Amerigo Wang discovered that HFS filesystem did not correctly validate disk structures. If a user were tricked into mounting a specially crafted HFS filesystem, a remote attacker could crash the system or gain root privileges. Notes: Bugs: Priority: medium Discovered-by: Amerigo Wang Assigned-to: ogasawara CVSS: Patches_linux-source-2.6.15: upstream_linux-source-2.6.15: released (2.6.33~rc1) dapper_linux-source-2.6.15: released (2.6.15-55.82) hardy_linux-source-2.6.15: DNE intrepid_linux-source-2.6.15: DNE jaunty_linux-source-2.6.15: DNE karmic_linux-source-2.6.15: DNE devel_linux-source-2.6.15: DNE Patches_linux: upstream: ec81aecb29668ad71f699f4e7b96ec46691895b6 upstream_linux: released (2.6.33~rc1) dapper_linux: DNE hardy_linux: released (2.6.24-27.65) intrepid_linux: released (2.6.27-17.45) jaunty_linux: released (2.6.28-18.59) karmic_linux: released (2.6.31-19.56) devel_linux: not-affected