Linked by Petur on Tue 8th Mar 2011 17:48 UTC
Thread beginning with comment 465341
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.
Features
Linked by Thom Holwerda on 05/24/13 17:26 UTC
Linked by Thom Holwerda on 05/21/13 21:38 UTC
Linked by Thom Holwerda on 05/20/13 11:29 UTC
Linked by Thom Holwerda on 05/18/13 21:33 UTC
Linked by David Adams on 05/16/13 4:23 UTC
Linked by Thom Holwerda on 05/11/13 21:41 UTC
Linked by Thom Holwerda on 05/08/13 14:22 UTC
Linked by Thom Holwerda on 05/02/13 15:28 UTC
Linked by Thom Holwerda on 04/29/13 21:06 UTC
Linked by Thom Holwerda on 04/24/13 22:24 UTC
More Features »
Sponsored Links



Member since:
2010-03-08
Looks like it
http://caiaq.com/index_en.html
http://www.globalsecuritymag.com/Vigil-nce-Linux-kernel-buffer,2011...
The sound/usb/caiaq directory implements the support of USB devices from the Native Instruments company.
The snd_usb_caiaq_audio_init() and snd_usb_caiaq_midi_init() functions copy the name of the USB device in a 80 bytes array. However, if the name provided by the USB device is longer, a buffer overflow occurs.
An attacker can therefore insert a USB device with a long name, in order to create an overflow in caiaq, leading to a denial of service or to code execution.
(Putting some memory regions on W and X access privileges at the same time... Them fool... DEP is not here for nothing !)
Edited 2011-03-08 20:56 UTC