PT-2020-7060 · Linux+2 · Linux Kernel+2

Rafael Dominguez Vega

·

Published

2011-10-20

·

Updated

2020-02-12

·

CVE-2009-4067

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.27
Description The issue is related to a buffer overflow in the auerswald probe function within the Auerswald Linux USB driver. This allows physically proximate attackers to execute arbitrary code, cause a denial of service via a crafted USB device, or take full control of the system.
Recommendations For Linux kernel versions prior to 2.6.27, update to version 2.6.27 or later to resolve the issue. As a temporary workaround, consider disabling the use of USB devices from untrusted sources to minimize the risk of exploitation. Restrict physical access to systems running affected kernel versions to prevent attackers from using crafted USB devices.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4067
DSA-2310-1
RHSA-2011:1386
RHSA-2011_1386

Affected Products

Linux Kernel
Red Hat
Suse