8.8
CVE-2019-17666
- EPSS 3.02%
- Veröffentlicht 17.10.2019 02:15:13
- Zuletzt bearbeitet 21.11.2024 04:32:44
- Erkennungen
rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer overflow.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 3.16.77
Linux ≫ Linux Kernel Version >= 3.17 < 4.4.199
Linux ≫ Linux Kernel Version >= 4.5 < 4.9.199
Linux ≫ Linux Kernel Version >= 4.10 < 4.14.152
Linux ≫ Linux Kernel Version >= 4.15 < 4.19.82
Linux ≫ Linux Kernel Version >= 4.20 < 5.2
Linux ≫ Linux Kernel Version >= 5.3 < 5.3.9
Debian ≫ Debian Linux Version 8.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.04
Canonical ≫ Ubuntu Linux Version 19.10
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.02% | 0.857 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 8.3 | 6.5 | 10 |
AV:A/AC:L/Au:N/C:C/I:C/A:C
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html
https://access.redhat.com/errata/RHSA-2020:0740
https://access.redhat.com/errata/RHSA-2020:0543
https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html
https://usn.ubuntu.com/4184-1/
https://usn.ubuntu.com/4185-1/
https://usn.ubuntu.com/4186-1/
https://usn.ubuntu.com/4186-2/
https://access.redhat.com/errata/RHSA-2020:0661
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00064.html
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00010.html
https://security.netapp.com/advisory/ntap-20191031-0005/
https://access.redhat.com/errata/RHSA-2020:0328
https://access.redhat.com/errata/RHSA-2020:0339
https://usn.ubuntu.com/4183-1/
https://arstechnica.com/information-technology/2019/10/unpatched-linux-flaw-may-let-attackers-crash-or-compromise-nearby-devices/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TRBP4O6D2SQ2NHCRHTJONGCZLWOIV5MN/
https://lkml.org/lkml/2019/10/16/1226
https://twitter.com/nicowaisman/status/1184864519316758535