SB2014022804 - Buffer overflow in Linux kernel



SB2014022804 - Buffer overflow in Linux kernel

Published: February 28, 2014 Updated: August 10, 2020

Security Bulletin ID SB2014022804
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Buffer overflow (CVE-ID: CVE-2014-1690)

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

The help function in net/netfilter/nf_nat_irc.c in the Linux kernel before 3.12.8 allows remote attackers to obtain sensitive information from kernel memory by establishing an IRC DCC session in which incorrect packet data is transmitted during use of the NAT mangle feature.


Remediation

Install update from vendor's website.