Lucene search

K
cveCanonicalCVE-2010-2959
HistorySep 08, 2010 - 8:00 p.m.

CVE-2010-2959

2010-09-0820:00:03
CWE-190
canonical
web.nvd.nist.gov
61
8
cve-2010-2959
linux kernel
integer overflow
controller area network
can
arbitrary code execution
denial of service
system crash
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

High

EPSS

0.002

Percentile

60.9%

Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows attackers to execute arbitrary code or cause a denial of service (system crash) via crafted CAN traffic.

Affected configurations

Nvd
Node
linuxlinux_kernelRange<2.6.27.53
OR
linuxlinux_kernelRange2.6.322.6.32.21
OR
linuxlinux_kernelRange2.6.342.6.34.6
OR
linuxlinux_kernelRange2.6.352.6.35.4
Node
fedoraprojectfedoraMatch12
Node
debiandebian_linuxMatch5.0
Node
opensuseopensuseMatch11.3
OR
suselinux_enterprise_desktopMatch11sp1
OR
suselinux_enterprise_high_availability_extensionMatch11sp1
OR
suselinux_enterprise_real_timeMatch11sp1
OR
suselinux_enterprise_serverMatch11sp1
VendorProductVersionCPE
linuxlinux_kernel*cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
fedoraprojectfedora12cpe:2.3:o:fedoraproject:fedora:12:*:*:*:*:*:*:*
debiandebian_linux5.0cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*
opensuseopensuse11.3cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:*
suselinux_enterprise_desktop11cpe:2.3:o:suse:linux_enterprise_desktop:11:sp1:*:*:*:*:*:*
suselinux_enterprise_high_availability_extension11cpe:2.3:o:suse:linux_enterprise_high_availability_extension:11:sp1:*:*:*:*:*:*
suselinux_enterprise_real_time11cpe:2.3:o:suse:linux_enterprise_real_time:11:sp1:*:*:*:*:*:*
suselinux_enterprise_server11cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:*:*:*:*

References

Social References

More

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

High

EPSS

0.002

Percentile

60.9%