v86d before 0.1.10 do not verify if received netlink messages are sent by the kernel. This could allow unprivileged users to manipulate the video mode and potentially other consequences.
References
Link | Resource |
---|---|
https://security-tracker.debian.org/tracker/CVE-2011-1070 | Third Party Advisory |
https://seclists.org/oss-sec/2011/q1/315 | Mailing List Third Party Advisory |
https://access.redhat.com/security/cve/cve-2011-1070 | Not Applicable Third Party Advisory |
Information
Published : 2019-11-13 17:15
Updated : 2020-08-18 08:05
NVD link : CVE-2011-1070
Mitre link : CVE-2011-1070
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
debian
- debian_linux
v86d_project
- v86d