Buffer overflow in format descriptor parsing in the uvc_parse_format function in drivers/media/video/uvc/uvc_driver.c in uvcvideo in the video4linux (V4L) implementation in the Linux kernel before 2.6.26.1 has unknown impact and attack vectors.
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
Link | Tags |
---|---|
http://secunia.com/advisories/31982 | third party advisory |
http://www.securityfocus.com/bid/30514 | third party advisory vdb entry |
http://www.mandriva.com/security/advisories?name=MDVSA-2008:223 | third party advisory vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.html | vendor advisory mailing list third party advisory |
http://lkml.org/lkml/2008/7/30/655 | third party advisory mailing list |
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.26.1 | release notes vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/44184 | third party advisory vdb entry |