CVE-2011-0712
HighMultiple buffer overflows in the caiaq Native Instruments USB audio functionality in the Linux kernel before 2.6.38-rc4-next-20110215 might allow attackers to cause a denial of service or possibly have unspecified other impact via a long USB device name, related to (1) the snd_usb_caiaq_audio_init function in sound/usb/caiaq/audio.c and (2) the snd_usb_caiaq_midi_init function in sound/usb/caiaq/midi.c.
CVSS 2.0 score
7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
Weakness type
CWE-120CVE-2011-0712 is classified as CWE-120
See CWE-120 on MITRE CWE for full details on this weakness type.
References
The following references provide additional information about CVE-2011-0712 including vendor advisories, patch commits, exploit details, and third-party analysis. Links are sourced from the NIST NVD database.
-
Broken Link
-
Securityfocushttp://www.securityfocus.com/bid/46419Third Party Advisory VDB Entry
-
Ubuntu Securityhttp://www.ubuntu.com/usn/USN-1146-1Third Party Advisory
-
Third Party Advisory VDB Entry
-
PatchKernel patch commithttp://git.kernel.org/?p=linux/kernel/git/tiwai/sound-2.6.git%3Ba=commit%3Bh=eaae55dac6b64c0616046436b294e69fc5311581
-
PatchKernel patch commithttp://www.openwall.com/lists/oss-security/2011/02/16/11
-
PatchKernel patch commithttp://www.openwall.com/lists/oss-security/2011/02/16/12
Frequently asked questions
-
What is CVE-2011-0712?
CVE-2011-0712 is a High severity Linux kernel vulnerability with a CVSS score of 7.2 out of 10 . CVE-2011-0712 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
What is the CVSS score for CVE-2011-0712?
CVE-2011-0712 has a CVSS score of 7.2 out of 10, rated High severity (CVSS 2.0). The vector string is
AV:L/AC:L/Au:N/C:C/I:C/A:C. -
Is there a patch available for CVE-2011-0712?
No patch is currently available for CVE-2011-0712. Monitor the NIST NVD and your Linux distribution's security advisories for updates.
-
Is CVE-2011-0712 actively exploited?
No — CVE-2011-0712 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.