---
title: "CVE-2011-3630\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2011-3630?format=md
keywords: index, follow
---

# CVE-2011-3630

Publication date 26 November 2019

Last updated 25 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**8.8 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2011-3630?format=md#impact-score)

Toggle side navigation

## Description

Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow
flaws because of the way directory trees with deeply nested directories are
processed. A remote attacker could provide a specially-crafted directory
tree, and trick the local user into consolidating it, leading to hardlink
executable crash, or, potentially arbitrary code execution with the
privileges of the user running the hardlink executable.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2011-3630?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| hardlink | 11.10 oneiric | Not affected |
| 11.04 natty | Not affected |
| 10.10 maverick | Not affected |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [tyhicks](https://launchpad.net/~tyhicks)

This is for the C version of hardlink

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

8.8 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 8.8 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3630)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2011-3630)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2011-3630)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2011-3630)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2011-3630>
