CVE-2005-3055
Vulnerability Summary
Timeline
Description
Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, which leads to a stale pointer reference.
CVSS Metrics
- v2.0•LOW•Score: 2.1AV:L/AC:L/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 0.09%• Percentile: 26%
Techniques & Countermeasures
- CWE-20•Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Affected Systems
- debian•debian_linux
3.1
- linux•linux_kernel
2.6.8 | 2.6.8:rc1 | 2.6.8:rc2 | 2.6.8:rc3 | 2.6.9:2.6.20 | 2.6.10 | 2.6.10:rc2 | 2.6.11 | 2.6.11:rc2 | 2.6.11:rc3 | 2.6.11:rc4 | 2.6.11.5 | 2.6.11.6 | 2.6.11.7 | 2.6.11.8 | 2.6.11.11 | 2.6.12:rc1 | 2.6.12:rc4 | 2.6.12:rc5 | 2.6.12.1 | 2.6.12.2 | 2.6.12.3 | 2.6.12.4 | 2.6.12.5 | 2.6.13 | 2.6.13:rc1 | 2.6.13:rc4 | 2.6.13:rc6 | 2.6.13:rc7 | 2.6.13.1 | 2.6.13.2 | 2.6.14:rc1 | 2.6.14:rc2
References (27)
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:235
- http://www.redhat.com/support/errata/RHSA-2006-0437.html
- http://secunia.com/advisories/17917
- http://www.securityfocus.com/advisories/9806
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:220
- http://www.redhat.com/support/errata/RHSA-2006-0579.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9472
- http://marc.info/?l=linux-kernel&m=112766129313883
- http://secunia.com/advisories/21136
- http://www.securityfocus.com/archive/1/419522/100/0/threaded
- http://secunia.com/advisories/21983
- http://secunia.com/advisories/21035
- http://www.redhat.com/support/errata/RHSA-2006-0575.html
- https://usn.ubuntu.com/219-1/
- http://www.redhat.com/support/errata/RHSA-2006-0580.html
- http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:218
- http://secunia.com/advisories/21465
- http://www.securityfocus.com/bid/14955
- http://secunia.com/advisories/17826
- http://www.vupen.com/english/advisories/2005/1863
- http://secunia.com/advisories/17918
- http://www.debian.org/security/2006/dsa-1017
- http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:219
- http://secunia.com/advisories/22417
- http://secunia.com/advisories/19374