CVE-2016-5342

HIGH

Description

Heap-based buffer overflow in the wcnss_wlan_write function in drivers/net/wireless/wcnss/wcnss_wlan.c in the wcnss_wlan device driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to cause a denial of service or possibly have unspecified other impact by writing to /dev/wcnss_wlan with an unexpected amount of data.

References

http://source.android.com/security/bulletin/2016-10-01.html

http://www.securityfocus.com/bid/92693

https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=579e796cb089324c55e0e689a180575ba81b23d9

https://www.codeaurora.org/buffer-overflow-vulnerability-wcnsswlanwrite-cve-2016-5342

Details

Source: MITRE

Published: 2016-08-30

Updated: 2020-08-04

Type: CWE-787

Risk Information

CVSS v2.0

Base Score: 7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.9

Severity: HIGH

CVSS v3.0

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:google:android:*:*:*:*:*:*:*:* versions up to 7.0 (inclusive)

Configuration 2

OR

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from 3.0 to 3.19.8 (inclusive)

Tenable Plugins

View all (1 total)

IDNameProductFamilySeverity
125101EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1513)NessusHuawei Local Security Checks
critical