PT-2006-7603 · Opensuse+2 · Usbvision-Kmp-Bigsmp+5

Marcel Holtmann

·

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2006-2936

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions usbvision-kmp-default versions (affected versions not specified) usbvision-kmp-debug versions (affected versions not specified) usbvision-kmp-bigsmp versions (affected versions not specified) usbvision-kmp-xenpae versions (affected versions not specified) usbvision-kmp-xen versions (affected versions not specified) Linux kernel versions 2.6.x up to 2.6.17
Description The issue concerns multiple vulnerabilities in the usbvision-kmp packages of the openSUSE operating system, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. Additionally, a vulnerability in the Linux kernel's ftdi sio driver allows local users to cause a denial of service by overloading the serial port with more data than the hardware can handle, resulting in memory consumption.
Recommendations For usbvision-kmp-default, consider disabling the vulnerable components until a patch is available. For usbvision-kmp-debug, restrict access to the vulnerable modules to minimize the risk of exploitation. For usbvision-kmp-bigsmp, avoid using the vulnerable functions until the issue is resolved. For usbvision-kmp-xenpae, consider applying configuration changes to mitigate the risk. For usbvision-kmp-xen, restrict access to the vulnerable parameters to minimize the risk of exploitation. For Linux kernel versions 2.6.x up to 2.6.17, update to a version later than 2.6.17 to resolve the issue.

Fix

DoS

Weakness Enumeration

Related Identifiers

BDU:2015-04883
BDU:2015-04884
BDU:2015-04885
BDU:2015-04886
BDU:2015-04887
CVE-2006-2936
DSA-1184-2
RHSA-2006:0617
RHSA-2006_0617

Affected Products

Linux Kernel
Red Hat
Usbvision-Kmp-Bigsmp
Usbvision-Kmp-Debug
Usbvision-Kmp-Default
Usbvision-Kmp-Xenpae