PT-2014-8746 · Linux+5 · Linux Kernel+5

Published

2014-11-24

·

Updated

2018-01-05

·

CVE-2014-8884

CVSS v2.0

6.1

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.17.4
Description The issue is a stack-based buffer overflow in the ttusbdecfe dvbs diseqc send master cmd function, which can be triggered by a large message length in an ioctl call. This can cause a denial of service, resulting in a system crash, or potentially allow local users to gain privileges.
Recommendations For Linux kernel versions prior to 3.17.4, update to version 3.17.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the ttusbdecfe dvbs diseqc send master cmd function to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2381
ALT-PU-2015-1794
CESA-2015_0290
CESA-2015_0864
CVE-2014-8884
DLA-118-1
DSA-3093-1
OPENSUSE-SU-2014_1669-1
RHSA-2015:0290
RHSA-2015:0782
RHSA-2015:0864
RHSA-2015_0290
RHSA-2015_0864
SUSE-RU-2015:0621-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2441-1
USN-2442-1
USN-2443-1
USN-2444-1
USN-2465-1
USN-2466-1
USN-2467-1
USN-2468-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu