Description
Multiple buffer overflows in the si4713_write_econtrol_string function in drivers/media/radio/si4713-i2c.c in the Linux kernel before 2.6.39.4 on the N900 platform might allow local users to cause a denial of service or have unspecified other impact via a crafted s_ext_ctrls operation with a (1) V4L2_CID_RDS_TX_PS_NAME or (2) V4L2_CID_RDS_TX_RADIO_TEXT control ID.
References (6)
Core 6
Core References
Exploit, Third Party Advisory x_refsource_misc
http://xorl.wordpress.com/2011/07/24/cve-2011-2700-linux-kernel-si4713-i2c-buffer-overflow/
Broken Link x_refsource_confirm
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39.4
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/48804
Mailing List, Patch, Third Party Advisory mailing-list
x_refsource_mlist
http://openwall.com/lists/oss-security/2011/07/20/4
Mailing List, Patch, Third Party Advisory mailing-list
x_refsource_mlist
http://openwall.com/lists/oss-security/2011/07/20/6
Scores
EPSS
0.0006
EPSS Percentile
19.9%
Details
CWE
CWE-120
Status
published
Products (1)
linux/linux_kernel
< 2.6.39.4
Published
Sep 06, 2011
Tracked Since
Feb 18, 2026