PT-2014-5122 · Linux+5 · Linux Kernel+5

Ben Hawkes

·

Publicado

2014-09-09

·

Atualizado

2023-12-29

·

CVE-2014-3182

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.16.2
Description The issue is related to an array index error in the logi dj raw event function in drivers/hid/hid-logitech-dj.c. This error allows physically proximate attackers to execute arbitrary code or cause a denial of service (invalid kfree) via a crafted device that provides a malformed REPORT TYPE NOTIF DEVICE UNPAIRED value.
Recommendations For Linux kernel versions prior to 3.16.2, update to version 3.16.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the logi dj raw event function in drivers/hid/hid-logitech-dj.c to minimize the risk of exploitation.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-2106
ALT-PU-2015-1794
CESA-2014_1971
CVE-2014-3182
OPENSUSE-SU-2014_1669-1
OPENSUSE-SU-2014_1677-1
RHSA-2014:1318
RHSA-2014:1971
RHSA-2014_1971
USN-2376-1
USN-2377-1
USN-2394-1
USN-2395-1

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu