PT-2006-7603 · Opensuse+2 · Usbvision-Kmp-Bigsmp+5
Marcel Holtmann
·
Published
1970-01-01
·
Updated
2023-02-13
·
CVE-2006-2936
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
usbvision-kmp-default versions (affected versions not specified)
usbvision-kmp-debug versions (affected versions not specified)
usbvision-kmp-bigsmp versions (affected versions not specified)
usbvision-kmp-xenpae versions (affected versions not specified)
usbvision-kmp-xen versions (affected versions not specified)
Linux kernel versions 2.6.x up to 2.6.17
Description
The issue concerns multiple vulnerabilities in the usbvision-kmp packages of the openSUSE operating system, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. Additionally, a vulnerability in the Linux kernel's ftdi sio driver allows local users to cause a denial of service by overloading the serial port with more data than the hardware can handle, resulting in memory consumption.
Recommendations
For usbvision-kmp-default, consider disabling the vulnerable components until a patch is available.
For usbvision-kmp-debug, restrict access to the vulnerable modules to minimize the risk of exploitation.
For usbvision-kmp-bigsmp, avoid using the vulnerable functions until the issue is resolved.
For usbvision-kmp-xenpae, consider applying configuration changes to mitigate the risk.
For usbvision-kmp-xen, restrict access to the vulnerable parameters to minimize the risk of exploitation.
For Linux kernel versions 2.6.x up to 2.6.17, update to a version later than 2.6.17 to resolve the issue.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel
Red Hat
Usbvision-Kmp-Bigsmp
Usbvision-Kmp-Debug
Usbvision-Kmp-Default
Usbvision-Kmp-Xenpae