PT-2006-7603 · Opensuse+2 · Usbvision-Kmp-Bigsmp+5
Marcel Holtmann
·
Publicado
1970-01-01
·
Atualizado
2023-02-13
·
CVE-2006-2936
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
usbvision-kmp-default versions (affected versions not specified)
usbvision-kmp-debug versions (affected versions not specified)
usbvision-kmp-bigsmp versions (affected versions not specified)
usbvision-kmp-xenpae versions (affected versions not specified)
usbvision-kmp-xen versions (affected versions not specified)
Linux kernel versions 2.6.x up to 2.6.17
Description
The issue concerns multiple vulnerabilities in the usbvision-kmp packages of the openSUSE operating system, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. Additionally, a vulnerability in the Linux kernel's ftdi sio driver allows local users to cause a denial of service by overloading the serial port with more data than the hardware can handle, resulting in memory consumption.
Recommendations
For usbvision-kmp-default, consider disabling the vulnerable components until a patch is available.
For usbvision-kmp-debug, restrict access to the vulnerable modules to minimize the risk of exploitation.
For usbvision-kmp-bigsmp, avoid using the vulnerable functions until the issue is resolved.
For usbvision-kmp-xenpae, consider applying configuration changes to mitigate the risk.
For usbvision-kmp-xen, restrict access to the vulnerable parameters to minimize the risk of exploitation.
For Linux kernel versions 2.6.x up to 2.6.17, update to a version later than 2.6.17 to resolve the issue.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Linux Kernel
Red Hat
Usbvision-Kmp-Bigsmp
Usbvision-Kmp-Debug
Usbvision-Kmp-Default
Usbvision-Kmp-Xenpae