PT-2004-1745 · Ieee · Ieee 1394 Driver
Published
2004-07-13
·
Updated
2017-07-11
·
CVE-2004-0658
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IEEE 1394 (Firewire) driver versions 2.4 and 2.6
Description
The issue is related to an integer overflow in the hpsb alloc packet function, which can be exploited by local users to cause a denial of service or possibly execute arbitrary code. This can be achieved through the functions raw1394 write, state connected, handle remote request, or hpsb make writebpacket.
Recommendations
For IEEE 1394 (Firewire) driver version 2.4, consider disabling the raw1394 write function as a temporary workaround until a patch is available.
For IEEE 1394 (Firewire) driver version 2.6, restrict access to the state connected function to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ieee 1394 Driver