CVE-2014-3181
published 2014-09-28CVE-2014-3181: Multiple stack-based buffer overflows in the magicmouse_raw_event function in drivers/hid/hid-magicmouse.c in the Magic Mouse HID driver in the Linux kernel…
PriorityP430medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.76%
51.9th percentile
Multiple stack-based buffer overflows in the magicmouse_raw_event function in drivers/hid/hid-magicmouse.c in the Magic Mouse HID driver in the Linux kernel through 3.16.3 allow physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with an event.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.16.5-1 (bookworm) | linux 3.16.5-1 (bookworm) |
| linux | linux_kernel | >= 0 < 3.16.5-1 | 3.16.5-1 |
| linux | linux_kernel | >= 0 < 3.16.5-1 | 3.16.5-1 |
| linux | linux_kernel | >= 0 < 3.16.5-1 | 3.16.5-1 |
| linux | linux_kernel | >= 0 < 3.16.5-1 | 3.16.5-1 |
| linux | linux_kernel | >= 0 < 3.13.0-37.64 | 3.13.0-37.64 |
| linux | linux_kernel | >= 2.6.37 < 3.2.63 | 3.2.63 |
| linux | linux_kernel | >= 3.11 < 3.12.31 | 3.12.31 |
| linux | linux_kernel | >= 3.13 < 3.14.20 | 3.14.20 |
| linux | linux_kernel | >= 3.15 < 3.16.4 | 3.16.4 |
| linux | linux_kernel | >= 3.3 < 3.4.104 | 3.4.104 |
| linux | linux_kernel | >= 3.5 < 3.10.56 | 3.10.56 |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to cause a denial of service (out-of-bounds write) via a
specially crafted device. (CVE-2014-3184)
Several bounds check flaws allowing for buffer overflows were discovered in
the Linux kernel's Whiteheat USB serial driver. A physically proximate
attac
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
A bounds check error was discovered in the driver for the Logitech Unifying
receivers and devices. A physically proximate attacker could exploit this
flaw to to cause a denial of service (invalid kfree) or to execute
arbitrary code. (CVE-2014-3182)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to cause a deni
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
A bounds check error was discovered in the driver for the Logitech Unifying
receivers and devices. A physically proximate attacker could exploit this
flaw to to cause a denial of service (invalid kfree) or to execute
arbitrary code. (CVE-2014-3182)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to caus
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to cause a denial of service (out-of-bounds write) via a
specially crafted device. (CVE-2014-3184)
Several bounds check flaws allowing for buffer overflows were discovered in
the Linux kernel's Whiteheat USB serial driver. A physically proximate
attacker could exp
Red Hat
Kernel: HID: OOB write in magicmouse driver
vendor_redhat·2014-08-27·CVSS 6.9
CVE-2014-3181 [MEDIUM] CWE-787 Kernel: HID: OOB write in magicmouse driver
Kernel: HID: OOB write in magicmouse driver
Multiple stack-based buffer overflows in the magicmouse_raw_event function in drivers/hid/hid-magicmouse.c in the Magic Mouse HID driver in the Linux kernel through 3.16.3 allow physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with an event.
An out-of-bounds write flaw was found in the way the Apple Magic Mouse/Trackpad multi-touch driver handled Human Interface Device (HID) reports with an invalid size. An attacker with physical access to the system could use this flaw to crash the system or, potentially, escalate their privileges on the system.
Statement: This issue does not affect the version
Debian
CVE-2014-3181: linux - Multiple stack-based buffer overflows in the magicmouse_raw_event function in dr...
vendor_debian·2014·CVSS 6.9
CVE-2014-3181 [MEDIUM] CVE-2014-3181: linux - Multiple stack-based buffer overflows in the magicmouse_raw_event function in dr...
Multiple stack-based buffer overflows in the magicmouse_raw_event function in drivers/hid/hid-magicmouse.c in the Magic Mouse HID driver in the Linux kernel through 3.16.3 allow physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with an event.
Scope: local
bookworm: resolved (fixed in 3.16.5-1)
bullseye: resolved (fixed in 3.16.5-1)
forky: resolved (fixed in 3.16.5-1)
sid: resolved (fixed in 3.16.5-1)
trixie: resolved (fixed in 3.16.5-1)
GHSA
GHSA-j99c-mhvh-v2g9: Multiple stack-based buffer overflows in the magicmouse_raw_event function in drivers/hid/hid-magicmouse
ghsa_unreviewed·2022-05-17
CVE-2014-3181 [MEDIUM] CWE-119 GHSA-j99c-mhvh-v2g9: Multiple stack-based buffer overflows in the magicmouse_raw_event function in drivers/hid/hid-magicmouse
Multiple stack-based buffer overflows in the magicmouse_raw_event function in drivers/hid/hid-magicmouse.c in the Magic Mouse HID driver in the Linux kernel through 3.16.3 allow physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with an event.
OSV
linux vulnerabilities
osv·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to cause a denial of service (out-of-bounds write) via a
specially crafted device. (CVE-2014-3184)
Several bounds check flaws allowing for buffer overflows were discovered in
the Linux kernel's Whiteheat USB serial driver. A physically proximate
attacker could exploit these flaws to cause a denial of service (system
crash) via a special
OSV
CVE-2014-3181: Multiple stack-based buffer overflows in the magicmouse_raw_event function in drivers/hid/hid-magicmouse
osv·2014-09-28·CVSS 6.9
CVE-2014-3181 [MEDIUM] CVE-2014-3181: Multiple stack-based buffer overflows in the magicmouse_raw_event function in drivers/hid/hid-magicmouse
Multiple stack-based buffer overflows in the magicmouse_raw_event function in drivers/hid/hid-magicmouse.c in the Magic Mouse HID driver in the Linux kernel through 3.16.3 allow physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with an event.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3181 Kernel: HID: OOB write in magicmouse driver
bugzilla·2014-09-12·CVSS 6.9
CVE-2014-3181 [MEDIUM] CVE-2014-3181 Kernel: HID: OOB write in magicmouse driver
CVE-2014-3181 Kernel: HID: OOB write in magicmouse driver
Linux kernel built with the Human Interface Device(HID) Bus support(CONFIG_HID)
along with a driver for Apple Magic Mouse/Trackpad multi-touch, is vulnerable
to an OOB write flaw. It could occur if a device offers an HID report of
arbitrary length.
A local user with physical access to the system could use this flaw to crash
the system resulting in DoS or potentially, escalate their privileges on the
system.
Upstream fix:
-> https://git.kernel.org/linus/c54def7bd64d7c0b6993336abcffb8444795bf38
Discussion:
Statement:
This issue does not affect the version of the kernel package as shipped with
Red Hat Enterprise Linux 5 and 6.
This issue affects the versions of Linux kernel as shipped with Red Hat Enterprise Linux 7 and Red Hat
Bugzilla
CVE-2014-3181 Kernel: HID: OOB write in magicmouse driver [fedora-all]
bugzilla·2014-09-12·CVSS 6.9
CVE-2014-3181 [MEDIUM] CVE-2014-3181 Kernel: HID: OOB write in magicmouse driver [fedora-all]
CVE-2014-3181 Kernel: HID: OOB write in magicmouse driver [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c54def7bd64d7c0b6993336abcffb8444795bf38http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1318.htmlhttp://www.openwall.com/lists/oss-security/2014/09/11/21http://www.securityfocus.com/bid/69779http://www.ubuntu.com/usn/USN-2376-1http://www.ubuntu.com/usn/USN-2377-1http://www.ubuntu.com/usn/USN-2378-1http://www.ubuntu.com/usn/USN-2379-1https://bugzilla.redhat.com/show_bug.cgi?id=1141173https://code.google.com/p/google-security-research/issues/detail?id=100https://github.com/torvalds/linux/commit/c54def7bd64d7c0b6993336abcffb8444795bf38http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c54def7bd64d7c0b6993336abcffb8444795bf38http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1318.htmlhttp://www.openwall.com/lists/oss-security/2014/09/11/21http://www.securityfocus.com/bid/69779http://www.ubuntu.com/usn/USN-2376-1http://www.ubuntu.com/usn/USN-2377-1http://www.ubuntu.com/usn/USN-2378-1http://www.ubuntu.com/usn/USN-2379-1https://bugzilla.redhat.com/show_bug.cgi?id=1141173https://code.google.com/p/google-security-research/issues/detail?id=100https://github.com/torvalds/linux/commit/c54def7bd64d7c0b6993336abcffb8444795bf38
2014-09-28
Published