CVE-2011-0712

HIGH
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Multiple buffer overflows in the caiaq Native Instruments USB audio functionality in the Linux kernel before 2.6.38-rc4-next-20110215 might allow attackers to cause a denial of service or possibly have unspecified other impact via a long USB device name, related to (1) the snd_usb_caiaq_audio_init function in sound/usb/caiaq/audio.c and (2) the snd_usb_caiaq_midi_init function in sound/usb/caiaq/midi.c.

References

http://git.kernel.org/?p=linux/kernel/git/tiwai/sound-2.6.git;a=commit;h=eaae55dac6b64c0616046436b294e69fc5311581

http://www.kernel.org/pub/linux/kernel/v2.6/next/patch-v2.6.38-rc4-next-20110215.bz2

http://www.openwall.com/lists/oss-security/2011/02/16/11

http://www.openwall.com/lists/oss-security/2011/02/16/12

http://www.openwall.com/lists/oss-security/2011/02/16/5

http://www.securityfocus.com/bid/46419

http://www.ubuntu.com/usn/USN-1146-1

https://bugzilla.redhat.com/show_bug.cgi?id=677881

https://exchange.xforce.ibmcloud.com/vulnerabilities/65461

Details

Source: MITRE

Published: 2011-02-18

Updated: 2020-08-11

Type: CWE-120

Risk Information

CVSS v2

Base Score: 7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.9

Severity: HIGH

Tenable Plugins

View all (19 total)

IDNameProductFamilySeverity
75879openSUSE Security Update : kernel (openSUSE-SU-2011:0416-1)NessusSuSE Local Security Checks
high
75554openSUSE Security Update : kernel (openSUSE-SU-2011:0399-1)NessusSuSE Local Security Checks
high
68416Oracle Linux 5 / 6 : Unbreakable Enterprise kernel (ELSA-2011-2015)NessusOracle Linux Local Security Checks
high
68273Oracle Linux 6 : kernel (ELSA-2011-0498)NessusOracle Linux Local Security Checks
high
65103Ubuntu 10.04 LTS / 10.10 : linux-mvl-dove vulnerabilities (USN-1093-1)NessusUbuntu Local Security Checks
high
61035Scientific Linux Security Update : kernel on SL6.x i386/x86_64NessusScientific Linux Local Security Checks
high
56285Debian DSA-2310-1 : linux-2.6 - privilege escalation/denial of service/information leakNessusDebian Local Security Checks
medium
56190USN-1202-1 : linux-ti-omap4 vulnerabilitiesNessusUbuntu Local Security Checks
high
55785Ubuntu 10.04 LTS : linux-lts-backport-maverick vulnerabilities (USN-1187-1)NessusUbuntu Local Security Checks
high
55591Ubuntu 11.04 : linux vulnerabilities (USN-1167-1)NessusUbuntu Local Security Checks
medium
55530USN-1164-1 : linux-fsl-imx51 vulnerabilitiesNessusUbuntu Local Security Checks
high
55454Ubuntu 10.10 : linux vulnerabilities (USN-1160-1)NessusUbuntu Local Security Checks
high
55109Ubuntu 8.04 LTS : linux vulnerabilities (USN-1146-1)NessusUbuntu Local Security Checks
high
55104Ubuntu 10.04 LTS : linux, linux-ec2 vulnerabilities (USN-1141-1)NessusUbuntu Local Security Checks
high
53867RHEL 6 : kernel (RHSA-2011:0498)NessusRed Hat Local Security Checks
high
53740openSUSE Security Update : kernel (openSUSE-SU-2011:0346-1)NessusSuSE Local Security Checks
high
53571SuSE 11.1 Security Update : Linux kernel (SAT Patch Number 4376)NessusSuSE Local Security Checks
high
53570SuSE 11.1 Security Update : Linux kernel (SAT Patch Numbers 4384 / 4386)NessusSuSE Local Security Checks
high
52597SuSE 11.1 Security Update : Linux kernel (SAT Patch Numbers 4039 / 4042 / 4043)NessusSuSE Local Security Checks
high