Linux Kernel Auerswald USB Device Driver Buffer Overflow Vulnerability
BID:48687
Info
Linux Kernel Auerswald USB Device Driver Buffer Overflow Vulnerability
| Bugtraq ID: | 48687 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-4067 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 19 2009 12:00AM |
| Updated: | Dec 13 2013 12:39PM |
| Credit: | R. Dominguez Veg |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 SuSE SUSE Linux Enterprise Server 10 SP4 SuSE SUSE Linux Enterprise Server 10 SP3 LTSS SuSE SUSE Linux Enterprise SDK 10 SP4 SuSE SUSE Linux Enterprise Desktop 10 SP4 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 5 OpenVZ Project OpenVZ 2.6.32-feoktistov.1 OpenVZ Project OpenVZ 2.6.32 OpenVZ Project OpenVZ 042stab039.10 OpenVZ Project OpenVZ 042stab037.1 OpenVZ Project OpenVZ 028stab092.2 OpenVZ Project OpenVZ 028stab091.1 OpenVZ Project OpenVZ 028stab089.1 OpenVZ Project OpenVZ 028stab085.2 OpenVZ Project OpenVZ 028stab081.1 OpenVZ Project OpenVZ 023stab054.1 OpenVZ Project OpenVZ 023stab053.2 Linux kernel 2.6.26 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
OpenVZ Project OpenVZ 028stab095.1 |
Discussion
Linux Kernel Auerswald USB Device Driver Buffer Overflow Vulnerability
The Auerswald USB Device Driver for the Linux kernel is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code with superuser privileges, facilitating the complete compromise of affected computers. Failed exploit attempts will likely crash the kernel, denying service to legitimate users.
Linux kernel 2.6.26 is vulnerable; prior versions may also be affected.
The Auerswald USB Device Driver for the Linux kernel is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code with superuser privileges, facilitating the complete compromise of affected computers. Failed exploit attempts will likely crash the kernel, denying service to legitimate users.
Linux kernel 2.6.26 is vulnerable; prior versions may also be affected.
Exploit / POC
Linux Kernel Auerswald USB Device Driver Buffer Overflow Vulnerability
The following proof-of-concept code is available:
The following proof-of-concept code is available:
Solution / Fix
Linux Kernel Auerswald USB Device Driver Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Linux Kernel Auerswald USB Device Driver Buffer Overflow Vulnerability
References:
References:
- Bug 722393 - (CVE-2009-4067) CVE-2009-4067 kernel: usb: buffer overflow in auers (RedHat)
- Download/kernel/rhel5/028stab095.1 (OpenVZ)
- Linux Homepage (Linux)
- Linux USB Device Driver - Buffer Overflow (MWRinfosecurity)