CVE-2014-8884
published 2014-11-30CVE-2014-8884: Stack-based buffer overflow in the ttusbdecfe_dvbs_diseqc_send_master_cmd function in drivers/media/usb/ttusb-dec/ttusbdecfe.c in the Linux kernel before…
PriorityP425medium6.1CVSS 2.0
AVLACLAuNCPIPAC
EPSS
0.64%
47.1th percentile
Stack-based buffer overflow in the ttusbdecfe_dvbs_diseqc_send_master_cmd function in drivers/media/usb/ttusb-dec/ttusbdecfe.c in the Linux kernel before 3.17.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via a large message length in an ioctl call.
Affected
180 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.16.7-ckt2-1 (bookworm) | linux 3.16.7-ckt2-1 (bookworm) |
| linux | linux_kernel | <= 3.17.3 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.06.1MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:C
osv6.1MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-01-13·CVSS 5.0
CVE-2014-7841 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A null pointer dereference flaw was discovered in the the Linux kernel's
SCTP implementation when ASCONF is used. A remote attacker could exploit
this flaw to cause a denial of service (system crash) via a malformed INIT
chunk. (CVE-2014-7841)
A race condition with MMIO and PIO transactions in the KVM (Kernel Virtual
Machine) subsystem of the Linux kernel was discovered. A guest OS user
could exploit this flaw to cause a denial of service (guest OS crash) via a
specially crafted application. (CVE-2014-7842)
Miloš Prchlík reported a flaw in how the ARM64 platform handles a single
byte overflow in __clear_user. A local user could exploit this flaw to
cause a denial of service (syst
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-01-13·CVSS 5.0
CVE-2014-7841 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A null pointer dereference flaw was discovered in the the Linux kernel's
SCTP implementation when ASCONF is used. A remote attacker could exploit
this flaw to cause a denial of service (system crash) via a malformed INIT
chunk. (CVE-2014-7841)
A race condition with MMIO and PIO transactions in the KVM (Kernel Virtual
Machine) subsystem of the Linux kernel was discovered. A guest OS user
could exploit this flaw to cause a denial of service (guest OS crash) via a
specially crafted application. (CVE-2014-7842)
Miloš Prchlík reported a flaw in how the ARM64 platform handles a single
byte overflow in __clear_user. A local user could exploit this flaw to
cause a denial of service (system crash) by
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-01-13·CVSS 5.0
CVE-2014-7841 [MEDIUM] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A null pointer dereference flaw was discovered in the the Linux kernel's
SCTP implementation when ASCONF is used. A remote attacker could exploit
this flaw to cause a denial of service (system crash) via a malformed INIT
chunk. (CVE-2014-7841)
A race condition with MMIO and PIO transactions in the KVM (Kernel Virtual
Machine) subsystem of the Linux kernel was discovered. A guest OS user
could exploit this flaw to cause a denial of service (guest OS crash) via a
specially crafted application. (CVE-2014-7842)
Miloš Prchlík reported a flaw in how the ARM64 platform handles a single
byte overflow in __clear_user. A local user could exploit this flaw to
cause a denial of service (syst
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2014-12-12·CVSS 7.5
CVE-2014-3673 [HIGH] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
A flaw in the handling of malformed ASCONF chunks by SCTP (Stream Control
Transmission Protocol) implementation in the Linux kernel was discovered. A
remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2014-3673)
A flaw in the handling of duplicate ASCONF chunks by SCTP (Stream Control
Transmission Protocol) implementation in the Linux
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-12-12·CVSS 7.8
CVE-2014-7825 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Lutomirski discovered that the Linux kernel does not properly handle
faults associated with the Stack Segment (SS) register in the x86
architecture. A local attacker could exploit this flaw to gain
administrative privileges. (CVE-2014-9322)
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
Rabin Vincent, Robert Swiecki, Russell King discovered that the ftrace
subsystem of the Linux kernel does not properly handle private s
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-12-12·CVSS 7.5
CVE-2014-3673 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
A flaw in the handling of malformed ASCONF chunks by SCTP (Stream Control
Transmission Protocol) implementation in the Linux kernel was discovered. A
remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2014-3673)
A flaw in the handling of duplicate ASCONF chunks by SCTP (Stream Control
Transmission Protocol) implementation in the Linux kerne
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-12-12·CVSS 7.8
CVE-2014-7825 [HIGH] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Rabin Vincent, Robert Swiecki, Russell King discovered that the ftrace
subsystem of the Linux kernel does not properly handle private syscall
numbers. A local user could exploit this flaw to cause a denial of service
(OOPS). (CVE-2014-7826)
Rabin Vincent, Robert Swiecki, Russell Kinglaw discovered a flaw in how the
perf subsystem of the Linux kernel handles private systecall numbers. A
local user could exploit this to cause a denial of service (OOPS) or bypass
ASLR protections via a crafted application. (CVE-2014-7825)
A null pointer dereference flaw was discovered in the the Linux kernel's
SCTP implementation when ASCONF is used. A remote attacker could exploit
this flaw to cause a d
Red Hat
kernel: usb: buffer overflow in ttusb-dec
vendor_redhat·2014-11-14·CVSS 6.1
CVE-2014-8884 [MEDIUM] CWE-121 kernel: usb: buffer overflow in ttusb-dec
kernel: usb: buffer overflow in ttusb-dec
Stack-based buffer overflow in the ttusbdecfe_dvbs_diseqc_send_master_cmd function in drivers/media/usb/ttusb-dec/ttusbdecfe.c in the Linux kernel before 3.17.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via a large message length in an ioctl call.
A stack-based buffer overflow flaw was found in the TechnoTrend/Hauppauge DEC USB device driver. A local user with write access to the corresponding device could use this flaw to crash the kernel or, potentially, elevate their privileges on the system.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2.
Future kernel updates for Red Hat Enterprise Linux 6 and 7 may addre
Debian
CVE-2014-8884: linux - Stack-based buffer overflow in the ttusbdecfe_dvbs_diseqc_send_master_cmd functi...
vendor_debian·2014·CVSS 6.1
CVE-2014-8884 [MEDIUM] CVE-2014-8884: linux - Stack-based buffer overflow in the ttusbdecfe_dvbs_diseqc_send_master_cmd functi...
Stack-based buffer overflow in the ttusbdecfe_dvbs_diseqc_send_master_cmd function in drivers/media/usb/ttusb-dec/ttusbdecfe.c in the Linux kernel before 3.17.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via a large message length in an ioctl call.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt2-1)
bullseye: resolved (fixed in 3.16.7-ckt2-1)
forky: resolved (fixed in 3.16.7-ckt2-1)
sid: resolved (fixed in 3.16.7-ckt2-1)
trixie: resolved (fixed in 3.16.7-ckt2-1)
GHSA
GHSA-f8j8-r858-m4h4: Stack-based buffer overflow in the ttusbdecfe_dvbs_diseqc_send_master_cmd function in drivers/media/usb/ttusb-dec/ttusbdecfe
ghsa_unreviewed·2022-05-14
CVE-2014-8884 [MEDIUM] CWE-119 GHSA-f8j8-r858-m4h4: Stack-based buffer overflow in the ttusbdecfe_dvbs_diseqc_send_master_cmd function in drivers/media/usb/ttusb-dec/ttusbdecfe
Stack-based buffer overflow in the ttusbdecfe_dvbs_diseqc_send_master_cmd function in drivers/media/usb/ttusb-dec/ttusbdecfe.c in the Linux kernel before 3.17.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via a large message length in an ioctl call.
OSV
linux vulnerabilities
osv·2015-01-13·CVSS 5.0
CVE-2014-7841 [MEDIUM] linux vulnerabilities
linux vulnerabilities
A null pointer dereference flaw was discovered in the the Linux kernel's
SCTP implementation when ASCONF is used. A remote attacker could exploit
this flaw to cause a denial of service (system crash) via a malformed INIT
chunk. (CVE-2014-7841)
A race condition with MMIO and PIO transactions in the KVM (Kernel Virtual
Machine) subsystem of the Linux kernel was discovered. A guest OS user
could exploit this flaw to cause a denial of service (guest OS crash) via a
specially crafted application. (CVE-2014-7842)
Miloš Prchlík reported a flaw in how the ARM64 platform handles a single
byte overflow in __clear_user. A local user could exploit this flaw to
cause a denial of service (system crash) by reading one byte beyond a
/dev/zero page boundary. (CVE-2014-7843)
A stac
OSV
linux-lts-utopic vulnerabilities
osv·2015-01-13·CVSS 5.0
CVE-2014-7841 [MEDIUM] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
A null pointer dereference flaw was discovered in the the Linux kernel's
SCTP implementation when ASCONF is used. A remote attacker could exploit
this flaw to cause a denial of service (system crash) via a malformed INIT
chunk. (CVE-2014-7841)
A race condition with MMIO and PIO transactions in the KVM (Kernel Virtual
Machine) subsystem of the Linux kernel was discovered. A guest OS user
could exploit this flaw to cause a denial of service (guest OS crash) via a
specially crafted application. (CVE-2014-7842)
Miloš Prchlík reported a flaw in how the ARM64 platform handles a single
byte overflow in __clear_user. A local user could exploit this flaw to
cause a denial of service (system crash) by reading one byte beyond a
/dev/zero page boundary. (CVE-2014-78
OSV
CVE-2014-8884: Stack-based buffer overflow in the ttusbdecfe_dvbs_diseqc_send_master_cmd function in drivers/media/usb/ttusb-dec/ttusbdecfe
osv·2014-11-30·CVSS 6.1
CVE-2014-8884 [MEDIUM] CVE-2014-8884: Stack-based buffer overflow in the ttusbdecfe_dvbs_diseqc_send_master_cmd function in drivers/media/usb/ttusb-dec/ttusbdecfe
Stack-based buffer overflow in the ttusbdecfe_dvbs_diseqc_send_master_cmd function in drivers/media/usb/ttusb-dec/ttusbdecfe.c in the Linux kernel before 3.17.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via a large message length in an ioctl call.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-8884 kernel: usb: buffer overflow in ttusb-dec [fedora-all]
bugzilla·2014-11-23·CVSS 6.1
CVE-2014-8884 [MEDIUM] CVE-2014-8884 kernel: usb: buffer overflow in ttusb-dec [fedora-all]
CVE-2014-8884 kernel: usb: buffer overflow in ttusb-dec [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. W
Bugzilla
CVE-2014-8884 kernel: usb: buffer overflow in ttusb-dec
bugzilla·2014-11-14·CVSS 6.1
CVE-2014-8884 [MEDIUM] CVE-2014-8884 kernel: usb: buffer overflow in ttusb-dec
CVE-2014-8884 kernel: usb: buffer overflow in ttusb-dec
Linux kernel built with TechnoTrend/Hauppauge DEC USB driver support is vulnerable to a stack-based buffer overflow flaw.
A local user with write access to the corresponding device could use this flaw to crash the kernel or, potentially, elevate their privileges.
Please note that in order to exploit this issue the TechnoTrend/Hauppauge DEC USB device needs to be plugged in on the system.
Upstream fix:
-> https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f2e323ec96077642d397bb1c355def536d489d16
Reference:
-> http://seclists.org/oss-sec/2014/q4/611
Discussion:
CVE id has been assigned to this issue:
http://seclists.org/oss-sec/2014/q4/615
---
Created kernel tracking bugs for this issue:
Affects: fedora
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f2e323ec96077642d397bb1c355def536d489d16http://rhn.redhat.com/errata/RHSA-2015-0290.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0782.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0864.htmlhttp://secunia.com/advisories/62305http://www.debian.org/security/2014/dsa-3093http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.17.4http://www.openwall.com/lists/oss-security/2014/11/14/7https://bugzilla.redhat.com/show_bug.cgi?id=1164266https://github.com/torvalds/linux/commit/f2e323ec96077642d397bb1c355def536d489d16http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f2e323ec96077642d397bb1c355def536d489d16http://rhn.redhat.com/errata/RHSA-2015-0290.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0782.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0864.htmlhttp://secunia.com/advisories/62305http://www.debian.org/security/2014/dsa-3093http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.17.4http://www.openwall.com/lists/oss-security/2014/11/14/7https://bugzilla.redhat.com/show_bug.cgi?id=1164266https://github.com/torvalds/linux/commit/f2e323ec96077642d397bb1c355def536d489d16
2014-11-30
Published