CVE-2008-3496
Buffer overflow in format descriptor parsing in the uvc_parse_format function in drivers/media/video/uvc/uvc_driver.c in uvcvideo in the video4linux (V4L) implementation in the Linux kernel before 2.6.26.1 has unknown impact and attack vectors.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in format descriptor parsing in the uvc_parse_format function in drivers/media/video/uvc/uvc_driver.c in uvcvideo in the video4linux (V4L) implementation in the Linux kernel before 2.6.26.1 has unknown impact and attack vectors.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 3.28% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- linux/linux kernel
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.htmlMailing List, Third Party Advisory
- http://lkml.org/lkml/2008/7/30/655Third Party Advisory
- http://secunia.com/advisories/31982Third Party Advisory
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.26.1Release Notes, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:223Third Party Advisory
- http://www.securityfocus.com/bid/30514Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44184Third Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.htmlMailing List, Third Party Advisory
- http://lkml.org/lkml/2008/7/30/655Third Party Advisory
- http://secunia.com/advisories/31982Third Party Advisory
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.26.1Release Notes, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:223Third Party Advisory
- http://www.securityfocus.com/bid/30514Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44184Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.