Search
Contactez-nous Suivez-nous sur Twitter En francais English Language
 

De la Théorie à la pratique

Freely subscribe to our NEWSLETTER

Newsletter FR

Newsletter EN

Vulnérabilités

Unsubscribe











Vigil@nce - Linux kernel: buffer overflow via caiaq

February 2011 by Vigil@nce

This bulletin was written by Vigil@nce : http://vigilance.fr/

SYNTHESIS OF THE VULNERABILITY

An attacker can insert a USB device with a long name, in order to create an overflow in caiaq, leading to a denial of service or to code execution.

Severity: 1/4

Creation date: 16/02/2011

IMPACTED PRODUCTS

- Linux kernel

DESCRIPTION OF THE VULNERABILITY

The sound/usb/caiaq directory implements the support of USB devices from the Native Instruments company.

The snd_usb_caiaq_audio_init() and snd_usb_caiaq_midi_init() functions copy the name of the USB device in a 80 bytes array. However, if the name provided by the USB device is longer, a buffer overflow occurs.

An attacker can therefore insert a USB device with a long name, in order to create an overflow in caiaq, leading to a denial of service or to code execution.

ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN

http://vigilance.fr/vulnerability/L...


See previous articles

    

See next articles

Last events

Key players in security to meet in Lyon - Technology Against Crime – an International Forum on Technologies for a Safer World

Some 600 international security professionals from the public and private sectors will meet on 8 and 9 July 2013 at the Lyon Convention Centre (Cité Centre de Congrès) for the first international forum of its kind, bringing together senior representatives from the worlds of technology, security and industry to develop technological responses to evolving security challenges.


    

See all events











Your podcast Here

New, you can have your Podcast here. Contact us for more information ask:
Marc Brami
Phone: +33 1 40 92 05 55
Mail: ipsimp@free.fr

All new podcasts