CVE-2006-2935
The dvd_read_bca function in the DVD handling code in drivers/cdrom/cdrom.c in Linux kernel 2.2.16, and later versions, assigns the wrong value to a length variable, which allows local users to execute arbitrary code via a crafted USB Storage device…
Does this matter?
Lower severity and a low EPSS score (0.57%). Track it; it rarely justifies an emergency change on its own.
Description
The dvd_read_bca function in the DVD handling code in drivers/cdrom/cdrom.c in Linux kernel 2.2.16, and later versions, assigns the wrong value to a length variable, which allows local users to execute arbitrary code via a crafted USB Storage device that triggers a buffer overflow.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.57% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- linux/linux kernel · debian/debian linux · canonical/ubuntu linux
- Source
- secalert@redhat.com
References
- http://bugzilla.kernel.org/show_bug.cgi?id=2966Issue Tracking, Vendor Advisory
- http://secunia.com/advisories/21179Broken Link
- http://secunia.com/advisories/21298Broken Link
- http://secunia.com/advisories/21498Broken Link
- http://secunia.com/advisories/21605Broken Link
- http://secunia.com/advisories/21614Broken Link
- http://secunia.com/advisories/21695Broken Link
- http://secunia.com/advisories/21934Broken Link
- http://secunia.com/advisories/22082Broken Link
- http://secunia.com/advisories/22093Broken Link
- http://secunia.com/advisories/22174Broken Link
- http://secunia.com/advisories/22497Broken Link
- http://secunia.com/advisories/22822Broken Link
- http://secunia.com/advisories/23064Broken Link
- http://secunia.com/advisories/23788Broken Link
- http://secunia.com/advisories/24288Broken Link
- http://support.avaya.com/elmodocs2/security/ASA-2006-203.htmThird Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2006-254.htmThird Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2007-078.htmThird Party Advisory
- http://www.debian.org/security/2006/dsa-1183Third Party Advisory
- http://www.debian.org/security/2006/dsa-1184Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:150Broken Link
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:151Broken Link
- http://www.novell.com/linux/security/advisories/2006_42_kernel.htmlBroken Link
- http://www.novell.com/linux/security/advisories/2006_47_kernel.htmlBroken Link
- http://www.novell.com/linux/security/advisories/2006_49_kernel.htmlBroken Link
- http://www.novell.com/linux/security/advisories/2006_64_kernel.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2006-0617.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2006-0710.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2007-0012.htmlBroken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.