CVE-2014-3185
published 2014-09-28CVE-2014-3185: Multiple buffer overflows in the command_port_read_callback function in drivers/usb/serial/whiteheat.c in the Whiteheat USB Serial Driver in the Linux kernel…
PriorityP432medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.60%
45.2th percentile
Multiple buffer overflows in the command_port_read_callback function in drivers/usb/serial/whiteheat.c in the Whiteheat USB Serial Driver in the Linux kernel before 3.16.2 allow physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with a bulk response.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.16.2-2 (bookworm) | linux 3.16.2-2 (bookworm) |
| linux | linux_kernel | < 3.2.63 | 3.2.63 |
| linux | linux_kernel | >= 0 < 3.16.2-2 | 3.16.2-2 |
| linux | linux_kernel | >= 0 < 3.16.2-2 | 3.16.2-2 |
| linux | linux_kernel | >= 0 < 3.16.2-2 | 3.16.2-2 |
| linux | linux_kernel | >= 0 < 3.16.2-2 | 3.16.2-2 |
| linux | linux_kernel | >= 0 < 3.13.0-37.64 | 3.13.0-37.64 |
| linux | linux_kernel | >= 3.11 < 3.12.29 | 3.12.29 |
| linux | linux_kernel | >= 3.13 < 3.14.18 | 3.14.18 |
| linux | linux_kernel | >= 3.15 < 3.16.2 | 3.16.2 |
| linux | linux_kernel | >= 3.3 < 3.4.104 | 3.4.104 |
| linux | linux_kernel | >= 3.5 < 3.10.54 | 3.10.54 |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| php5 | php5 | >= 0 < 5.5.9+dfsg-1ubuntu4.16 | 5.5.9+dfsg-1ubuntu4.16 |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_msrc6.9MEDIUM
vendor_redhat6.9MEDIUM
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
CVE-2014-3185: NIST NVD Details: https://nvd
vendor_msrc·2024-06-11·CVSS 6.9
CVE-2014-3185 [MEDIUM] CVE-2014-3185: NIST NVD Details: https://nvd
NIST NVD Details: https://nvd.nist.gov/vuln/detail/CVE-2014-3185
Mariner: Mariner
[email protected]: [email protected]
Customer Action Required: Yes
Remediation: kernel
Reference: https://nvd.nist.gov/vuln/detail/CVE-2014-3185
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to cause a denial of service (out-of-bounds write) via a
specially crafted device. (CVE-2014-3184)
Several bounds check flaws allowing for buffer overflows were discovered in
the Linux kernel's Whiteheat USB serial driver. A physically proximate
attac
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
A bounds check error was discovered in the driver for the Logitech Unifying
receivers and devices. A physically proximate attacker could exploit this
flaw to to cause a denial of service (invalid kfree) or to execute
arbitrary code. (CVE-2014-3182)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to cause a deni
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 4.7
CVE-2014-3184 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to cause a denial of service (out-of-bounds write) via a
specially crafted device. (CVE-2014-3184)
Several bounds check flaws allowing for buffer overflows were discovered in
the Linux kernel's Whiteheat USB serial driver. A physically proximate
attacker could exploit these flaws to cause a denial of service (system
crash) via a specially crafted device. (CVE-2014-3185)
A flaw was discovered in the Linux kernel's UDF filesystem (used on some
CD-ROMs and DVDs) when processing indirect ICBs. An attacker who can cause
CD, DVD or image file w
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
A bounds check error was discovered in the driver for the Logitech Unifying
receivers and devices. A physically proximate attacker could exploit this
flaw to to cause a denial of service (invalid kfree) or to execute
arbitrary code. (CVE-2014-3182)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to caus
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to cause a denial of service (out-of-bounds write) via a
specially crafted device. (CVE-2014-3184)
Several bounds check flaws allowing for buffer overflows were discovered in
the Linux kernel's Whiteheat USB serial driver. A physically proximate
attacker could exp
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 4.7
CVE-2014-3184 [MEDIUM] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to cause a denial of service (out-of-bounds write) via a
specially crafted device. (CVE-2014-3184)
Several bounds check flaws allowing for buffer overflows were discovered in
the Linux kernel's Whiteheat USB serial driver. A physically proximate
attacker could exploit these flaws to cause a denial of service (system
crash) via a specially crafted device. (CVE-2014-3185)
A flaw was discovered in the Linux kernel's UDF filesystem (used on some
CD-ROMs and DVDs) when processing indirect ICBs. An attacker who can cause
CD, DVD or image
Red Hat
Kernel: USB serial: memory corruption flaw
vendor_redhat·2014-08-24·CVSS 6.9
CVE-2014-3185 [MEDIUM] Kernel: USB serial: memory corruption flaw
Kernel: USB serial: memory corruption flaw
Multiple buffer overflows in the command_port_read_callback function in drivers/usb/serial/whiteheat.c in the Whiteheat USB Serial Driver in the Linux kernel before 3.16.2 allow physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with a bulk response.
A memory corruption flaw was found in the way the USB ConnectTech WhiteHEAT serial driver processed completion commands sent via USB Request Blocks buffers. An attacker with physical access to the system could use this flaw to crash the system or, potentially, escalate their privileges on the system.
Statement: This issue affects the versi
Debian
CVE-2014-3185: linux - Multiple buffer overflows in the command_port_read_callback function in drivers/...
vendor_debian·2014·CVSS 6.9
CVE-2014-3185 [MEDIUM] CVE-2014-3185: linux - Multiple buffer overflows in the command_port_read_callback function in drivers/...
Multiple buffer overflows in the command_port_read_callback function in drivers/usb/serial/whiteheat.c in the Whiteheat USB Serial Driver in the Linux kernel before 3.16.2 allow physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with a bulk response.
Scope: local
bookworm: resolved (fixed in 3.16.2-2)
bullseye: resolved (fixed in 3.16.2-2)
forky: resolved (fixed in 3.16.2-2)
sid: resolved (fixed in 3.16.2-2)
trixie: resolved (fixed in 3.16.2-2)
GHSA
GHSA-2jr7-m5j8-2vf4: Multiple buffer overflows in the command_port_read_callback function in drivers/usb/serial/whiteheat
ghsa_unreviewed·2022-05-17
CVE-2014-3185 [MEDIUM] CWE-119 GHSA-2jr7-m5j8-2vf4: Multiple buffer overflows in the command_port_read_callback function in drivers/usb/serial/whiteheat
Multiple buffer overflows in the command_port_read_callback function in drivers/usb/serial/whiteheat.c in the Whiteheat USB Serial Driver in the Linux kernel before 3.16.2 allow physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with a bulk response.
OSV
php5 vulnerabilities
osv·2016-04-21·CVSS 4.3
CVE-2014-9767 php5 vulnerabilities
php5 vulnerabilities
It was discovered that the PHP Zip extension incorrectly handled
directories when processing certain zip files. A remote attacker could
possibly use this issue to create arbitrary directories. (CVE-2014-9767)
It was discovered that the PHP Soap client incorrectly validated data
types. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2015-8835, CVE-2016-3185)
It was discovered that the PHP MySQL native driver incorrectly handled TLS
connections to MySQL databases. A machine-in-the-middle attacker could possibly
use this issue to downgrade and snoop on TLS connections. This
vulnerability is known as BACKRONYM. (CVE-2015-8838)
It was discovered that PHP incorrectly handled the imag
OSV
linux vulnerabilities
osv·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to cause a denial of service (out-of-bounds write) via a
specially crafted device. (CVE-2014-3184)
Several bounds check flaws allowing for buffer overflows were discovered in
the Linux kernel's Whiteheat USB serial driver. A physically proximate
attacker could exploit these flaws to cause a denial of service (system
crash) via a special
OSV
CVE-2014-3185: Multiple buffer overflows in the command_port_read_callback function in drivers/usb/serial/whiteheat
osv·2014-09-28·CVSS 6.9
CVE-2014-3185 [MEDIUM] CVE-2014-3185: Multiple buffer overflows in the command_port_read_callback function in drivers/usb/serial/whiteheat
Multiple buffer overflows in the command_port_read_callback function in drivers/usb/serial/whiteheat.c in the Whiteheat USB Serial Driver in the Linux kernel before 3.16.2 allow physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with a bulk response.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3185 Kernel: USB serial: memory corruption flaw [fedora-all]
bugzilla·2014-09-13·CVSS 6.9
CVE-2014-3185 [MEDIUM] CVE-2014-3185 Kernel: USB serial: memory corruption flaw [fedora-all]
CVE-2014-3185 Kernel: USB serial: memory corruption flaw [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
Bugzilla
CVE-2014-3185 Kernel: USB serial: memory corruption flaw
bugzilla·2014-09-13·CVSS 6.9
CVE-2014-3185 [MEDIUM] CVE-2014-3185 Kernel: USB serial: memory corruption flaw
CVE-2014-3185 Kernel: USB serial: memory corruption flaw
Linux kernel built with the USB Serial Converter support(USB_SERIAL) along with
a USB ConnectTech WhiteHEAT Serial Driver(CONFIG_USB_SERIAL_WHITEHEAT) is
vulnerable to a memory corruption flaw. It could occur when reading completion
commands via USB Request Blocks buffers.
A local user with physical access to the system could use this flaw to corrupt
kernel memory area or crash the system kernel resulting in DoS.
Upstream fix:
-> https://git.kernel.org/linus/6817ae225cd650fb1c3295d769298c38b1eba818
Discussion:
Statement:
This issue affects the versions of the Linux kernel as shipped with
Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2. Future kernel
updates for Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterpri
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6817ae225cd650fb1c3295d769298c38b1eba818http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1318.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0284.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.16.2http://www.openwall.com/lists/oss-security/2014/09/11/21http://www.securityfocus.com/bid/69781http://www.ubuntu.com/usn/USN-2374-1http://www.ubuntu.com/usn/USN-2375-1http://www.ubuntu.com/usn/USN-2376-1http://www.ubuntu.com/usn/USN-2377-1http://www.ubuntu.com/usn/USN-2378-1http://www.ubuntu.com/usn/USN-2379-1https://bugzilla.redhat.com/show_bug.cgi?id=1141400https://code.google.com/p/google-security-research/issues/detail?id=98https://github.com/torvalds/linux/commit/6817ae225cd650fb1c3295d769298c38b1eba818http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6817ae225cd650fb1c3295d769298c38b1eba818http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1318.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0284.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.16.2http://www.openwall.com/lists/oss-security/2014/09/11/21http://www.securityfocus.com/bid/69781http://www.ubuntu.com/usn/USN-2374-1http://www.ubuntu.com/usn/USN-2375-1http://www.ubuntu.com/usn/USN-2376-1http://www.ubuntu.com/usn/USN-2377-1http://www.ubuntu.com/usn/USN-2378-1http://www.ubuntu.com/usn/USN-2379-1https://bugzilla.redhat.com/show_bug.cgi?id=1141400https://code.google.com/p/google-security-research/issues/detail?id=98https://github.com/torvalds/linux/commit/6817ae225cd650fb1c3295d769298c38b1eba818
2014-09-28
Published