LWN.net Logo

usbmuxd: code execution

Package(s):usbmuxd CVE #(s):CVE-2012-0065
Created:February 1, 2012 Updated:April 11, 2013
Description: It turns out that usbmuxd does not perform proper bounds checking when processing the SerialNumber field provided by USB devices. A local attacker with a suitably modified USB device could exploit this failure to run arbitrary code as the "usbmux" user.
Alerts:
Ubuntu USN-1354-1 2012-02-01
Fedora FEDORA-2012-1192 2012-02-17
Fedora FEDORA-2012-1213 2012-02-17
Gentoo 201203-11 2012-03-05
openSUSE openSUSE-SU-2012:0345-1 2012-03-09
Mandriva MDVSA-2012:133 2012-08-16
Mageia MGASA-2012-0228 2012-08-18
Mandriva MDVSA-2013:133 2013-04-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds