Lucene search

K
cve[email protected]CVE-2014-4656
HistoryJul 03, 2014 - 4:22 a.m.

CVE-2014-4656

2014-07-0304:22:15
CWE-190
web.nvd.nist.gov
78
cve-2014-4656
linux kernel
alsa control
integer overflow
denial of service
nvd

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

5.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.2%

Multiple integer overflows in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allow local users to cause a denial of service by leveraging /dev/snd/controlCX access, related to (1) index values in the snd_ctl_add function and (2) numid values in the snd_ctl_remove_numid_conflict function.

Affected configurations

NVD
Node
linuxlinux_kernelRange<3.15.2
Node
suselinux_enterprise_serverMatch10sp4ltss
Node
canonicalubuntu_linuxMatch12.04esm
Node
redhatenterprise_linux_desktopMatch6.0
OR
redhatenterprise_linux_eusMatch6.6
OR
redhatenterprise_linux_serverMatch6.0
OR
redhatenterprise_linux_server_ausMatch6.6
OR
redhatenterprise_linux_server_tusMatch6.6
OR
redhatenterprise_linux_workstationMatch6.0

References

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

5.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.2%