PT-2010-5667 · Suse+1 · Kernel-Desktop-Devel+3
Mauro Carvalho Chehab
·
Published
1970-01-01
·
Updated
2023-02-13
·
CVE-2011-2700
CVSS v2.0
5.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
btrfs-kmp-xen versions (affected versions not specified)
btrfs-kmp-pae versions (affected versions not specified)
kernel-desktop-devel versions (affected versions not specified)
Linux kernel versions prior to 2.6.39.4
Description
The issue involves multiple vulnerabilities in the Linux kernel and SUSE Linux Enterprise packages, which can be exploited locally to compromise the confidentiality, integrity, and availability of protected information. In the Linux kernel, multiple buffer overflows in the
si4713 write econtrol string function may allow local users to cause a denial of service or have unspecified other impact via a crafted s ext ctrls operation with a (1) V4L2 CID RDS TX PS NAME or (2) V4L2 CID RDS TX RADIO TEXT control ID.Recommendations
For btrfs-kmp-xen, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For btrfs-kmp-pae, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For kernel-desktop-devel, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Linux kernel versions prior to 2.6.39.4, update to version 2.6.39.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the
si4713 write econtrol string function in the drivers/media/radio/si4713-i2c.c file until a patch is available.Exploit
Buffer Overflow
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Btrfs-Kmp-Pae
Btrfs-Kmp-Xen
Kernel-Desktop-Devel