CVE-2006-4145 describes a denial-of-service vulnerability in the Universal Disk Format (UDF) filesystem driver within Linux kernel versions 2.6.17 and earlier. A local attacker can trigger a system hang and crash by performing specific operations on truncated files, such as using the dd command. This vulnerability has a CVSS score of 4.9, indicating a low attack complexity and requiring local access, but with a complete impact on system availability. While there is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, the CVE has garnered significant community discussion with 10 mentions, suggesting awareness despite its age.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
2.6.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.0:*:*:*:*:*:*:* | ||
2.6.1CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.1:*:*:*:*:*:*:* | ||
2.6.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.2:*:*:*:*:*:*:* | ||
2.6.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.