Description
The Orinoco driver (orinoco.c) in Linux kernel 2.6.13 and earlier does not properly clear memory from a previously used packet whose length is increased, which allows remote attackers to obtain sensitive information.
References (30)
Core 30
Core References
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2005:235
Vendor Advisory x_refsource_confirm
http://www.kernel.org/hg/linux-2.6/?cmd=changeset%3Bnode=feecb2ffde28639e60ede769c6f817dc536c677b
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2006-0140.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-808.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/17917
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/18684
Third Party Advisory, VDB Entry vendor-advisory
x_refsource_suse
http://www.securityfocus.com/advisories/9806
Vendor Advisory vendor-advisory
x_refsource_mandrake
http://www.mandriva.com/security/advisories?name=MDKSA-2005:220
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/17364
Third Party Advisory third-party-advisory
x_refsource_sreason
http://securityreason.com/securityalert/75
Third Party Advisory, VDB Entry vendor-advisory
x_refsource_suse
http://www.securityfocus.com/archive/1/419522/100/0/threaded
Third Party Advisory, VDB Entry vendor-advisory
x_refsource_fedora
http://www.securityfocus.com/archive/1/428058/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11332
Vendor Advisory vendor-advisory
x_refsource_ubuntu
https://usn.ubuntu.com/219-1/
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2006-0190.html
Vendor Advisory vendor-advisory
x_refsource_mandrake
http://www.mandriva.com/security/advisories?name=MDKSA-2005:218
Third Party Advisory, VDB Entry vendor-advisory
x_refsource_fedora
http://www.securityfocus.com/archive/1/428028/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/15085
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/17280
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/17826
Third Party Advisory, VDB Entry vendor-advisory
x_refsource_fedora
http://www.securityfocus.com/advisories/9549
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/17918
Third Party Advisory, VDB Entry vendor-advisory
x_refsource_fedora
http://www.securityfocus.com/archive/1/427980/100/0/threaded
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2006/dsa-1017
Vendor Advisory vendor-advisory
x_refsource_mandrake
http://www.mandriva.com/security/advisories?name=MDKSA-2005:219
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/17114
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/19374
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2006-0191.html
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=112914754708402&w=2
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/18562
Scores
EPSS
0.0354
EPSS Percentile
88.2%
Details
Status
published
Products (1)
linux/linux_kernel
< 2.6.13
Published
Oct 12, 2005
Tracked Since
Feb 18, 2026