PT-2013-6330 · Opensuse+5 · Crash-Eppic-Debuginfo+147

Publicado

1970-01-01

·

Atualizado

2020-08-14

·

CVE-2014-4656

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions openSUSE kernel-default (affected versions not specified) openSUSE libipset3 (affected versions not specified) openSUSE ndiswrapper-kmp-pae (affected versions not specified) openSUSE hdjmod-kmp-xen (affected versions not specified) CentOS kernel-headers-2.6.32 (affected versions not specified) openSUSE kernel-trace-base-debuginfo (affected versions not specified) openSUSE cloop-debugsource (affected versions not specified) openSUSE crash-kmp-pae-debuginfo (affected versions not specified) openSUSE ipset-kmp-pae (affected versions not specified) openSUSE hdjmod-kmp-xen-debuginfo (affected versions not specified) openSUSE ipset-kmp-pae-debuginfo (affected versions not specified) openSUSE vhba-kmp-desktop-debuginfo (affected versions not specified) openSUSE iscsitarget-kmp-pae-debuginfo (affected versions not specified) openSUSE crash-debugsource (affected versions not specified) openSUSE iscsitarget-kmp-xen-debuginfo (affected versions not specified) openSUSE hdjmod-kmp-desktop-debuginfo (affected versions not specified) openSUSE kernel-xen (affected versions not specified) openSUSE hdjmod-debugsource (affected versions not specified) Red Hat Enterprise Linux kernel-debuginfo-common-i686 (affected versions not specified) Red Hat Enterprise Linux kernel-doc-2.6.32 (affected versions not specified) openSUSE crash (affected versions not specified) openSUSE crash-doc (affected versions not specified) openSUSE iscsitarget-kmp-xen (affected versions not specified) Red Hat Enterprise Linux kernel-debug-devel-2.6.32 (affected versions not specified) openSUSE iscsitarget-debugsource (affected versions not specified) openSUSE kernel-pae-devel-debuginfo (affected versions not specified) CentOS kernel-abi-whitelists-2.6.32 (affected versions not specified) openSUSE hdjmod-kmp-pae-debuginfo (affected versions not specified) openSUSE xtables-addons-kmp-default-debuginfo (affected versions not specified) openSUSE kernel-default-debuginfo (affected versions not specified) openSUSE kernel-vanilla-devel (affected versions not specified) openSUSE iscsitarget-kmp-desktop (affected versions not specified) openSUSE ndiswrapper-debuginfo (affected versions not specified) openSUSE kernel-pae-debugsource (affected versions not specified) openSUSE vhba-kmp-default (affected versions not specified) openSUSE kernel-trace-devel-debuginfo (affected versions not specified) openSUSE hdjmod-kmp-default-debuginfo (affected versions not specified) openSUSE cloop-kmp-xen-debuginfo (affected versions not specified) CentOS kernel-firmware-2.6.32 (affected versions not specified) Red Hat Enterprise Linux kernel-headers-2.6.32 (affected versions not specified) openSUSE kernel-vanilla-debuginfo (affected versions not specified) openSUSE vhba-kmp-xen-debuginfo (affected versions not specified) openSUSE ndiswrapper (affected versions not specified) openSUSE pcfclock-debuginfo (affected versions not specified) CentOS kernel-debug-2.6.32 (affected versions not specified) openSUSE cloop-kmp-desktop (affected versions not specified) openSUSE hdjmod-kmp-desktop (affected versions not specified) openSUSE kernel-ec2-debuginfo (affected versions not specified) openSUSE crash-gcore-debuginfo (affected versions not specified) openSUSE crash-kmp-default (affected versions not specified) openSUSE kernel-xen-base-debuginfo (affected versions not specified) Red Hat Enterprise Linux kernel-firmware-2.6.32 (affected versions not specified) openSUSE ipset-kmp-default-debuginfo (affected versions not specified) openSUSE libipset3 (affected versions not specified) openSUSE ndiswrapper-kmp-desktop-debuginfo (affected versions not specified) openSUSE crash-debuginfo (affected versions not specified) openSUSE kernel-ec2-base-debuginfo (affected versions not specified) openSUSE kernel-desktop (affected versions not specified) openSUSE xtables-addons-kmp-pae (affected versions not specified) openSUSE kernel-default-devel (affected versions not specified) openSUSE ndiswrapper-kmp-default-debuginfo (affected versions not specified) openSUSE crash-kmp-desktop (affected versions not specified) openSUSE kernel-vanilla-debugsource (affected versions not specified) openSUSE crash-eppic-debuginfo (affected versions not specified) openSUSE vhba-kmp-pae-debuginfo (affected versions not specified) openSUSE kernel-devel (affected versions not specified) openSUSE kernel-ec2-devel (affected versions not specified) openSUSE ipset-devel (affected versions not specified) openSUSE pcfclock (affected versions not specified) CentOS kernel-2.6.32 (affected versions not specified) openSUSE kernel-xen-base (affected versions not specified) openSUSE cloop-kmp-default-debuginfo (affected versions not specified) Red Hat Enterprise Linux kernel-debuginfo-2.6.32 (affected versions not specified) openSUSE kernel-xen-debuginfo (affected versions not specified) Red Hat Enterprise Linux kernel-2.6.32 (affected versions not specified) openSUSE kernel-ec2 (affected versions not specified) openSUSE kernel-debug-devel-debuginfo (affected versions not specified) openSUSE kernel-desktop-devel (affected versions not specified) openSUSE xtables-addons-kmp-default (affected versions not specified) Red Hat Enterprise Linux kernel-debug-2.6.32 (affected versions not specified) openSUSE pcfclock-kmp-pae (affected versions not specified) openSUSE ipset-debuginfo (affected versions not specified) openSUSE kernel-trace (affected versions not specified) openSUSE ndiswrapper-debugsource (affected versions not specified) openSUSE xtables-addons-kmp-desktop (affected versions not specified) openSUSE xtables-addons-kmp-xen (affected versions not specified) openSUSE xtables-addons-kmp-desktop-debuginfo (affected versions not specified) openSUSE kernel-debuginfo-common-i686 (affected versions not specified) openSUSE ipset-kmp-xen-debuginfo (affected versions not specified) openSUSE kernel-pae-debuginfo (affected versions not specified) openSUSE cloop (affected versions not specified) openSUSE kernel-debug-devel (affected versions not specified) openSUSE pcfclock-kmp-desktop-debuginfo (affected versions not specified) openSUSE ndiswrapper-kmp-pae (affected versions not specified) openSUSE crash-kmp-xen-debuginfo (affected versions not specified) openSUSE ipset-debugsource (affected versions not specified) openSUSE vhba-kmp-debugsource (affected versions not specified) openSUSE xtables-addons-kmp-xen-debuginfo (affected versions not specified) openSUSE xtables-addons-debuginfo (affected versions not specified) openSUSE kernel-debug-debuginfo (affected versions not specified) openSUSE kernel-syms (affected versions not specified) openSUSE kernel-ec2-devel-debuginfo (affected versions not specified) openSUSE kernel-trace-debugsource (affected versions not specified) openSUSE kernel-debug-base (affected versions not specified) openSUSE kernel-xen-devel (affected versions not specified) Red Hat Enterprise Linux kernel-devel-2.6.32 (affected versions not specified) openSUSE cloop-debuginfo (affected versions not specified) openSUSE vhba-kmp-pae (affected versions not specified) openSUSE pcfclock-kmp-default-debuginfo (affected versions not specified) openSUSE iscsitarget-kmp-default (affected versions not specified) openSUSE kernel-pae-base (affected versions not specified) openSUSE kernel-ec2-debugsource (affected versions not specified) openSUSE ipset (affected versions not specified) openSUSE ndiswrapper-kmp-desktop (affected versions not specified) openSUSE cloop-kmp-xen (affected versions not specified) openSUSE hdjmod-kmp-default (affected versions not specified) openSUSE kernel-vanilla-devel-debuginfo (affected versions not specified) openSUSE kernel-docs (affected versions not specified) openSUSE crash-gcore (affected versions not specified) openSUSE ipset-kmp-desktop (affected versions not specified) openSUSE kernel-ec2-devel (affected versions not specified) openSUSE crash-kmp-default-debuginfo (affected versions not specified) openSUSE kernel-ec2-base (affected versions not specified) openSUSE xtables-addons-debugsource (affected versions not specified) openSUSE kernel-vanilla (affected versions not specified) openSUSE pcfclock-kmp-default (affected versions not specified) openSUSE kernel-default-devel-debuginfo (affected versions not specified) openSUSE kernel-source-vanilla (affected versions not specified) openSUSE cloop-kmp-pae (affected versions not specified) openSUSE iscsitarget-kmp-desktop-debuginfo (affected versions not specified) Red Hat Enterprise Linux kernel-abi-whitelists-2.6.32 (affected versions not specified) openSUSE kernel-pae-base-debuginfo (affected versions not specified) openSUSE cloop-kmp-pae-debuginfo (affected versions not specified) CentOS kernel-debuginfo-2.6.32 (affected versions not specified) CentOS kernel-debug-devel-2.6.32 (affected versions not specified) CentOS kernel-doc-2.6.32 (affected versions not specified) openSUSE pcfclock-kmp-desktop (affected versions not specified) openSUSE kernel-pae (affected versions not specified) openSUSE kernel-debug-debugsource (affected versions not specified) openSUSE kernel-trace-debuginfo (affected versions not specified) openSUSE crash-eppic (affected versions not specified) openSUSE iscsitarget-kmp-default-debuginfo (affected versions not specified) openSUSE crash-kmp-pae (affected versions not specified) openSUSE kernel-default-base (affected versions not specified) openSUSE cloop-kmp-desktop-debuginfo (affected versions not specified) openSUSE kernel-xen-devel (affected versions not specified) openSUSE gfs2-kmp-xen (affected versions not specified) CentOS kernel-devel-2.6.32 (affected versions not specified) openSUSE cloop-kmp-default (affected versions not specified) openSUSE kernel-desktop-debugsource (affected versions not specified) openSUSE crash-kmp-desktop-debuginfo (affected versions not specified) openSUSE kernel-default-debugsource (affected versions not specified) openSUSE kernel-desktop-base (affected versions not specified) openSUSE kernel-pae-devel (affected versions not specified) openSUSE pcfclock-kmp-pae-debuginfo (affected versions not specified) openSUSE iscsitarget-kmp-pae (affected versions not specified) openSUSE vhba-kmp-xen (affected versions not specified) openSUSE iscsitarget-debuginfo (affected versions not specified) openSUSE pcfclock-debugsource (affected versions not specified) openSUSE hdjmod-kmp-pae (affected versions not specified) openSUSE kernel-xen-devel-debuginfo (affected versions not specified) openSUSE vhba-kmp-default-debuginfo (affected versions not specified) openSUSE kernel-pae-devel (affected versions not specified) openSUSE kernel-xen-debugsource (affected versions not specified) openSUSE crash-kmp-xen (affected versions not specified) openSUSE kernel-trace-devel (affected versions not specified) openSUSE ndiswrapper-kmp-default (affected versions not specified)
Description The issue is related to multiple integer overflows in the ALSA control implementation in the Linux kernel. The overflows occur in the snd ctl add function when handling index values and in the snd ctl remove numid conflict function when handling numid values. This can lead to a denial of service by leveraging /dev/snd/controlCX access. The vulnerability can be exploited remotely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Integer Overflow

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1825
ALT-PU-2014-1845
ALT-PU-2014-1846
ALT-PU-2014-1847
ALT-PU-2015-1794
BDU:2015-04307
BDU:2015-04308
BDU:2015-04309
BDU:2015-04310
BDU:2015-05685
BDU:2015-05686
BDU:2015-05687
BDU:2015-05688
BDU:2015-05689
BDU:2015-05690
BDU:2015-05691
BDU:2015-05692
BDU:2015-05693
BDU:2015-05694
BDU:2015-05695
BDU:2015-05696
BDU:2015-05697
BDU:2015-05698
BDU:2015-05699
BDU:2015-05700
BDU:2015-05701
BDU:2015-05702
BDU:2015-05703
BDU:2015-05704
BDU:2015-05705
BDU:2015-05706
BDU:2015-05707
BDU:2015-05708
BDU:2015-05709
BDU:2015-05710
BDU:2015-05711
BDU:2015-05712
BDU:2015-05713
BDU:2015-05714
BDU:2015-05715
BDU:2015-05716
BDU:2015-05717
BDU:2015-05718
BDU:2015-05719
BDU:2015-05720
BDU:2015-05721
BDU:2015-05722
BDU:2015-05723
BDU:2015-05724
BDU:2015-05725
BDU:2015-05726
BDU:2015-05727
BDU:2015-05728
BDU:2015-05729
BDU:2015-05730
BDU:2015-05731
BDU:2015-05732
BDU:2015-05733
BDU:2015-05734
BDU:2015-05735
BDU:2015-05736
BDU:2015-05737
BDU:2015-05738
BDU:2015-05739
BDU:2015-05740
BDU:2015-05741
BDU:2015-05742
BDU:2015-05743
BDU:2015-05744
BDU:2015-05745
BDU:2015-05746
BDU:2015-05747
BDU:2015-05748
BDU:2015-05749
BDU:2015-05750
BDU:2015-05751
BDU:2015-05752
BDU:2015-05753
BDU:2015-05754
BDU:2015-05755
BDU:2015-05756
BDU:2015-05757
BDU:2015-05758
BDU:2015-05759
BDU:2015-05760
BDU:2015-05761
BDU:2015-05762
BDU:2015-05763
BDU:2015-05764
BDU:2015-05765
BDU:2015-05766
BDU:2015-05767
BDU:2015-05768
BDU:2015-05769
BDU:2015-05770
BDU:2015-05771
BDU:2015-05772
BDU:2015-05773
BDU:2015-05774
BDU:2015-05775
BDU:2015-05776
BDU:2015-05777
BDU:2015-05778
BDU:2015-05779
BDU:2015-05780
BDU:2015-05781
BDU:2015-05782
BDU:2015-05783
BDU:2015-05784
BDU:2015-05785
BDU:2015-05786
BDU:2015-05787
BDU:2015-05788
BDU:2015-05789
BDU:2015-05790
BDU:2015-05791
BDU:2015-05792
BDU:2015-05793
BDU:2015-05794
BDU:2015-05795
BDU:2015-05796
BDU:2015-05797
BDU:2015-05798
BDU:2015-05799
BDU:2015-05800
BDU:2015-05801
BDU:2015-05802
BDU:2015-05803
BDU:2015-05804
BDU:2015-05805
BDU:2015-05806
BDU:2015-05807
BDU:2015-05808
BDU:2015-05809
BDU:2015-05810
BDU:2015-05811
BDU:2015-05812
BDU:2015-05813
BDU:2015-05814
BDU:2015-05815
BDU:2015-05816
BDU:2015-05817
BDU:2015-05818
BDU:2015-05819
BDU:2015-05820
BDU:2015-05821
BDU:2015-05822
BDU:2015-05823
BDU:2015-05824
BDU:2015-05825
BDU:2015-05826
BDU:2015-05827
BDU:2015-05828
BDU:2015-05829
BDU:2015-05830
BDU:2015-05831
BDU:2015-05832
BDU:2015-05833
BDU:2015-05834
BDU:2015-05835
BDU:2015-05836
BDU:2015-05837
BDU:2015-05838
BDU:2015-05839
BDU:2015-05840
BDU:2015-05841
BDU:2015-05842
BDU:2015-05843
BDU:2015-06239
BDU:2015-06241
BDU:2015-06245
BDU:2015-06246
BDU:2015-06247
BDU:2015-06248
BDU:2015-06249
BDU:2015-06251
BDU:2015-06255
BDU:2015-06258
BDU:2015-06260
BDU:2015-09204
BDU:2015-09205
BDU:2015-09206
BDU:2015-09207
BDU:2015-09208
BDU:2015-09209
BDU:2015-09210
BDU:2015-09211
BDU:2015-09212
BDU:2015-09213
BDU:2015-09214
CESA-2014_1971
CESA-2015_0087
CVE-2014-4656
DLA-0015-1
OPENSUSE-SU-2014_0957-1
OPENSUSE-SU-2014_0985-1
RHSA-2014:1083
RHSA-2014:1971
RHSA-2014_1971
RHSA-2015:0087
RHSA-2015_0087
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0652-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2332-1
USN-2333-1
USN-2334-1
USN-2335-1
USN-2336-1
USN-2337-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Cloop
Cloop-Debuginfo
Cloop-Debugsource
Cloop-Kmp-Default
Cloop-Kmp-Default-Debuginfo
Cloop-Kmp-Desktop
Cloop-Kmp-Desktop-Debuginfo
Cloop-Kmp-Pae
Cloop-Kmp-Pae-Debuginfo
Cloop-Kmp-Xen
Cloop-Kmp-Xen-Debuginfo
Crash
Crash-Debuginfo
Crash-Debugsource
Crash-Doc
Crash-Eppic
Crash-Eppic-Debuginfo
Crash-Gcore
Crash-Gcore-Debuginfo
Crash-Kmp-Default
Crash-Kmp-Default-Debuginfo
Crash-Kmp-Desktop
Crash-Kmp-Desktop-Debuginfo
Crash-Kmp-Pae
Crash-Kmp-Pae-Debuginfo
Crash-Kmp-Xen
Crash-Kmp-Xen-Debuginfo
Gfs2-Kmp-Xen
Hdjmod-Debugsource
Hdjmod-Kmp-Default
Hdjmod-Kmp-Default-Debuginfo
Hdjmod-Kmp-Desktop
Hdjmod-Kmp-Desktop-Debuginfo
Hdjmod-Kmp-Pae
Hdjmod-Kmp-Pae-Debuginfo
Hdjmod-Kmp-Xen
Ipset
Ipset-Debuginfo
Ipset-Debugsource
Ipset-Devel
Ipset-Kmp-Default-Debuginfo
Ipset-Kmp-Desktop
Ipset-Kmp-Pae
Ipset-Kmp-Pae-Debuginfo
Ipset-Kmp-Xen-Debuginfo
Iscsitarget-Debuginfo
Iscsitarget-Debugsource
Iscsitarget-Kmp-Default
Iscsitarget-Kmp-Default-Debuginfo
Iscsitarget-Kmp-Desktop
Iscsitarget-Kmp-Desktop-Debuginfo
Iscsitarget-Kmp-Pae
Iscsitarget-Kmp-Pae-Debuginfo
Iscsitarget-Kmp-Xen
Kernel
Kernel-Abi-Whitelists
Kernel-Debug
Kernel-Debug-Base
Kernel-Debug-Debuginfo
Kernel-Debug-Debugsource
Kernel-Debug-Devel
Kernel-Debug-Devel-Debuginfo
Kernel-Debuginfo-Common
Kernel-Default
Kernel-Default-Base
Kernel-Default-Debuginfo
Kernel-Default-Debugsource
Kernel-Default-Devel
Kernel-Desktop
Kernel-Desktop-Base
Kernel-Desktop-Debugsource
Kernel-Desktop-Devel
Kernel-Devel
Kernel-Doc
Kernel-Ec2
Kernel-Ec2-Base
Kernel-Ec2-Base-Debuginfo
Kernel-Ec2-Debuginfo
Kernel-Ec2-Debugsource
Kernel-Ec2-Devel
Kernel-Ec2-Devel-Debuginfo
Kernel-Firmware
Kernel-Headers
Kernel-Pae
Kernel-Pae-Base
Kernel-Trace-Base-Debuginfo
Kernel-Xenpae-Debuginfo
Kernel-Pae-Debugsource
Kernel-Pae-Devel
Kernel-Xen-Devel-Debuginfo
Kernel-Source-Vanilla
Kernel-Syms
Kernel-Trace
Kernel-Trace-Debuginfo
Kernel-Trace-Debugsource
Kernel-Trace-Devel
Kernel-Trace-Devel-Debuginfo
Kernel-Vanilla
Kernel-Vanilla-Debuginfo
Kernel-Vanilla-Debugsource
Kernel-Vanilla-Devel
Kernel-Vanilla-Devel-Debuginfo
Kernel-Xen
Kernel-Xen-Base
Kernel-Xen-Base-Debuginfo
Kernel-Xen-Debuginfo
Kernel-Xen-Debugsource
Kernel-Xen-Devel
Libipset3
Ndiswrapper
Ndiswrapper-Debuginfo
Ndiswrapper-Debugsource
Ndiswrapper-Kmp-Default
Ndiswrapper-Kmp-Default-Debuginfo
Ndiswrapper-Kmp-Desktop
Ndiswrapper-Kmp-Desktop-Debuginfo
Ndiswrapper-Kmp-Pae
Pcfclock
Pcfclock-Debuginfo
Pcfclock-Debugsource
Pcfclock-Kmp-Default
Pcfclock-Kmp-Default-Debuginfo
Pcfclock-Kmp-Desktop
Pcfclock-Kmp-Desktop-Debuginfo
Pcfclock-Kmp-Pae
Pcfclock-Kmp-Pae-Debuginfo
Vhba-Kmp-Debugsource
Vhba-Kmp-Default
Vhba-Kmp-Default-Debuginfo
Vhba-Kmp-Desktop-Debuginfo
Vhba-Kmp-Pae
Vhba-Kmp-Pae-Debuginfo
Vhba-Kmp-Xen
Vhba-Kmp-Xen-Debuginfo
Xtables-Addons-Debuginfo
Xtables-Addons-Debugsource
Xtables-Addons-Kmp-Default
Xtables-Addons-Kmp-Default-Debuginfo
Xtables-Addons-Kmp-Desktop
Xtables-Addons-Kmp-Desktop-Debuginfo
Xtables-Addons-Kmp-Pae
Xtables-Addons-Kmp-Xen
Xtables-Addons-Kmp-Pae-Debuginfo