7.8

CVE-2019-14814

Exploit

There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version >= 3.7 < 3.16.74
LinuxLinux Kernel Version >= 3.17 < 4.4.194
LinuxLinux Kernel Version >= 4.5 < 4.9.194
LinuxLinux Kernel Version >= 4.10 < 4.14.146
LinuxLinux Kernel Version >= 4.15 < 4.19.75
LinuxLinux Kernel Version >= 4.20 < 5.2.17
RedhatEnterprise Linux Version5.0
RedhatEnterprise Linux Version6.0
RedhatEnterprise Linux Version7.0
RedhatEnterprise Linux Version8.0
RedhatEnterprise Linux Eus Version8.1
RedhatEnterprise Linux Eus Version8.2
RedhatEnterprise Linux Eus Version8.4
DebianDebian Linux Version8.0
CanonicalUbuntu Linux Version14.04 SwEditionesm
CanonicalUbuntu Linux Version16.04 SwEditionesm
CanonicalUbuntu Linux Version18.04 SwEditionlts
CanonicalUbuntu Linux Version19.04
OpensuseLeap Version15.0
OpensuseLeap Version15.1
NetappService Processor Version-
NetappSolidfire Version-
NetappA700s Firmware Version-
   NetappA700s Version-
NetappA320 Firmware Version-
   NetappA320 Version-
NetappC190 Firmware Version-
   NetappC190 Version-
NetappA220 Firmware Version-
   NetappA220 Version-
NetappFas2720 Firmware Version-
   NetappFas2720 Version-
NetappFas2750 Firmware Version-
   NetappFas2750 Version-
NetappA800 Firmware Version-
   NetappA800 Version-
NetappH300s Firmware Version-
   NetappH300s Version-
NetappH500s Firmware Version-
   NetappH500s Version-
NetappH700s Firmware Version-
   NetappH700s Version-
NetappH300e Firmware Version-
   NetappH300e Version-
NetappH500e Firmware Version-
   NetappH500e Version-
NetappH700e Firmware Version-
   NetappH700e Version-
NetappH410s Firmware Version-
   NetappH410s Version-
NetappH410c Firmware Version-
   NetappH410c Version-
NetappH610s Firmware Version-
   NetappH610s Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.483
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
secalert@redhat.com 5.5 1.8 3.6
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-122 Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://usn.ubuntu.com/4163-1/
Third Party Advisory
https://usn.ubuntu.com/4163-2/
Third Party Advisory
https://seclists.org/bugtraq/2019/Nov/11
Patch
Third Party Advisory
Mailing List
https://usn.ubuntu.com/4162-1/
Third Party Advisory
https://usn.ubuntu.com/4162-2/
Third Party Advisory
https://usn.ubuntu.com/4157-1/
Third Party Advisory
https://usn.ubuntu.com/4157-2/
Third Party Advisory
http://www.openwall.com/lists/oss-security/2019/08/28/1
Patch
Third Party Advisory
Exploit
Mailing List
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14814
Patch
Third Party Advisory
Exploit
Issue Tracking
https://www.openwall.com/lists/oss-security/2019/08/28/1
Patch
Third Party Advisory
Exploit
Mailing List