Multiple integer signedness errors in the TIPC implementation in the Linux kernel before 2.6.36.2 allow local users to gain privileges via a crafted sendmsg call that triggers a heap-based buffer overflow, related to the tipc_msg_build function in net/tipc/msg.c and the verify_iovec function in net/core/iovec.c.
References
Information
Published : 2010-12-29 10:00
Updated : 2023-02-12 20:26
NVD link : CVE-2010-3859
Mitre link : CVE-2010-3859
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
debian
- debian_linux
linux
- linux_kernel