F5 Networks BIG-IP : Linux kernel vulnerability (K74413297)

Medium Nessus Plugin ID 104194

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

The report_fixup functions in the HID subsystem in the Linux kernel before 3.16.2 might allow physically proximate attackers to cause a denial of service (out-of-bounds write) via a crafted device that provides a small report descriptor, related to (1) drivers/hid/hid-cherry.c, (2) drivers/hid/hid-kye.c, (3) drivers/hid/hid-lg.c, (4) drivers/hid/hid-monterey.c, (5) drivers/hid/hid-petalynx.c, and (6) drivers/hid/hid-sunplus.c.
(CVE-2014-3184)

Impact

An attacker may be able to gain access to unauthorized information, perform unauthorized modification of data, or cause disruption of services. This vulnerability requires physical access to the device.

Solution

Upgrade to one of the non-vulnerable versions listed in the F5 Solution K74413297.

See Also

https://support.f5.com/csp/#/article/K74413297

Plugin Details

Severity: Medium

ID: 104194

File Name: f5_bigip_SOL74413297.nasl

Version: 3.3

Type: local

Published: 2017/10/27

Modified: 2018/07/10

Dependencies: 76940

Risk Information

Risk Factor: Medium

CVSSv2

Base Score: 4.7

Temporal Score: 3.5

Vector: CVSS2#AV:L/AC:M/Au:N/C:N/I:N/A:C

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:f5:big-ip_access_policy_manager, cpe:/a:f5:big-ip_advanced_firewall_manager, cpe:/a:f5:big-ip_application_acceleration_manager, cpe:/a:f5:big-ip_application_security_manager, cpe:/a:f5:big-ip_application_visibility_and_reporting, cpe:/a:f5:big-ip_global_traffic_manager, cpe:/a:f5:big-ip_link_controller, cpe:/a:f5:big-ip_local_traffic_manager, cpe:/a:f5:big-ip_policy_enforcement_manager, cpe:/a:f5:big-ip_webaccelerator, cpe:/h:f5:big-ip

Required KB Items: Host/local_checks_enabled, Host/BIG-IP/hotfix, Host/BIG-IP/modules, Host/BIG-IP/version, Settings/ParanoidReport

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2017/10/27

Reference Information

CVE: CVE-2014-3184

BID: 69768