oss-sec mailing list archives

Re: Multiple Linux USB driver CVE assignment


From: Ben Hawkes <hawkes () inertiawar com>
Date: Thu, 11 Sep 2014 14:26:12 -0700

And a final addition:

CVE-2014-3186 :
https://code.google.com/p/google-security-research/issues/detail?id=101
- "PicoLCD HID device driver pool overflow"

On Thu, Sep 11, 2014 at 1:32 PM, Ben Hawkes <hawkes () inertiawar com> wrote:
We've assigned the following CVEs:

CVE-2014-3182 :
https://code.google.com/p/google-security-research/issues/detail?id=89
- "Linux kernel hid-logitech-dj.c device_index arbitrary kfree"

CVE-2014-3183 :
https://code.google.com/p/google-security-research/issues/detail?id=90
- "Linux kernel hid-logitech-dj.c logi_dj_ll_raw_request heap
overflow"

CVE-2014-3184  :
https://code.google.com/p/google-security-research/issues/detail?id=91
- "Linux kernel HID report fixup multiple off-by-one issues"

CVE-2014-3185  :
https://code.google.com/p/google-security-research/issues/detail?id=98
- "Linux Kernel Buffer Overflow in Whiteheat USB Serial Driver"

CVE-2014-3181 :
https://code.google.com/p/google-security-research/issues/detail?id=100
- "Magic Mouse HID device driver overflow"

Thanks,
Ben


Current thread: