8.8

CVE-2019-3846

Exploit
A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 3.0 < 3.16.70
Linux ≫ Linux Kernel Version >= 3.17 < 4.4.186
Linux ≫ Linux Kernel Version >= 4.5 < 4.9.186
Linux ≫ Linux Kernel Version >= 4.10 < 4.14.134
Linux ≫ Linux Kernel Version >= 4.15 < 4.19.59
Linux ≫ Linux Kernel Version >= 4.20 < 5.1.18
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.04
Netapp ≫ A700s Firmware Version -
   Netapp ≫ A700s Version -
Netapp ≫ Cn1610 Firmware Version -
   Netapp ≫ Cn1610 Version -
Netapp ≫ H610s Firmware Version -
   Netapp ≫ H610s Version -
Netapp ≫ Hci Management Node Version -
Netapp ≫ Solidfire Version -
Fedoraproject ≫ Fedora Version 29
Fedoraproject ≫ Fedora Version 30
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Opensuse ≫ Leap Version 15.0
Opensuse ≫ Leap Version 15.1
Opensuse ≫ Leap Version 42.3
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.65% 0.92
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 8.3 6.5 10
AV:A/AC:L/Au:N/C:C/I:C/A:C
RedHat 8 2.1 5.9
CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-122 Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00039.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00048.html
Third Party Advisory
Mailing List
https://usn.ubuntu.com/4094-1/
Third Party Advisory
https://usn.ubuntu.com/4118-1/
Third Party Advisory
http://packetstormsecurity.com/files/154245/Kernel-Live-Patch-Security-Notice-LSN-0054-1.html
Third Party Advisory
VDB Entry
https://access.redhat.com/errata/RHSA-2020:0174
Third Party Advisory
https://usn.ubuntu.com/4095-1/
Third Party Advisory
https://usn.ubuntu.com/4095-2/
Third Party Advisory
http://packetstormsecurity.com/files/153702/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html
Third Party Advisory
VDB Entry
https://seclists.org/bugtraq/2019/Jul/33
Patch
Third Party Advisory
Mailing List
https://access.redhat.com/errata/RHSA-2019:2703
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2019/06/msg00010.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2019/06/msg00011.html
Third Party Advisory
Mailing List
https://seclists.org/bugtraq/2019/Jun/26
Third Party Advisory
Mailing List
https://www.debian.org/security/2019/dsa-4465
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2741
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00040.html
Third Party Advisory
Mailing List
https://usn.ubuntu.com/4117-1/
Third Party Advisory
http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.html
Third Party Advisory
VDB Entry
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J36BIJTKEPUOZKJNHQBUZA47RQONUKOI/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KLGWJKLMTBBB53D5QLS4HOY2EH246WBE/
https://security.netapp.com/advisory/ntap-20190710-0002/
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3055
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3076
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3089
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3846
Patch
Third Party Advisory
Issue Tracking
Mitigation
https://seclists.org/oss-sec/2019/q2/133
Third Party Advisory
Exploit
Mailing List
https://usn.ubuntu.com/4093-1/
Third Party Advisory