4

CVE-2010-4242

Exploit
The hci_uart_tty_open function in the HCI UART driver (drivers/bluetooth/hci_ldisc.c) in the Linux kernel 2.6.36, and possibly other versions, does not verify whether the tty has a write operation, which allows local users to cause a denial of service (NULL pointer dereference) via vectors related to the Bluetooth driver.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version2.6.36
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.363
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4 1.9 6.9
AV:L/AC:H/Au:N/C:N/I:N/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/46397
http://www.securityfocus.com/archive/1/520102/100/0/threaded
http://www.vmware.com/security/advisories/VMSA-2011-0012.html
http://secunia.com/advisories/42890
http://www.redhat.com/support/errata/RHSA-2011-0007.html
http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.html
http://secunia.com/advisories/43291
http://www.vupen.com/english/advisories/2011/0375
http://secunia.com/advisories/42789
http://www.redhat.com/support/errata/RHSA-2011-0004.html
http://www.vupen.com/english/advisories/2011/0024
http://secunia.com/advisories/42963
http://www.redhat.com/support/errata/RHSA-2011-0162.html
http://www.vupen.com/english/advisories/2011/0168
http://git.kernel.org/linus/c19483cc5e56ac5e22dd19cf25ba210ab1537773
Patch
http://www.securityfocus.com/bid/45014
http://xorl.wordpress.com/2010/12/01/cve-2010-4242-linux-kernel-bluetooth-hci-uart-invalid-pointer-access/
Patch
Exploit
https://bugzilla.redhat.com/show_bug.cgi?id=641410
Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/64617
https://lkml.org/lkml/2010/10/7/255