Tracker / CVE-2014-0196
CVE-2014-0196
Exploited Medium 5.5
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.
Affected products and versions
| canonical | ubuntu_linux |
|---|---|
| debian | debian_linux |
| f5 | big-ip_access_policy_manager · 11.1.0 → 11.5.1 |
| f5 | big-ip_advanced_firewall_manager · 11.3.0 → 11.5.1 |
| f5 | big-ip_analytics · 11.1.0 → 11.5.1 |
| f5 | big-ip_application_acceleration_manager · 11.4.0 → 11.5.1 |
| f5 | big-ip_application_security_manager · 11.1.0 → 11.5.1 |
| f5 | big-ip_edge_gateway · 11.1.0 → 11.3.0 |
| f5 | big-ip_global_traffic_manager · 11.1.0 → 11.5.1 |
| f5 | big-ip_link_controller · 11.1.0 → 11.5.1 |
| f5 | big-ip_local_traffic_manager · 11.1.0 → 11.5.1 |
| f5 | big-ip_policy_enforcement_manager · 11.3.0 → 11.5.1 |
| f5 | big-ip_protocol_security_module · 11.1.0 → 11.4.1 |
| f5 | big-ip_wan_optimization_manager · 11.1.0 → 11.3.0 |
| f5 | big-ip_webaccelerator · 11.1.0 → 11.3.0 |
| f5 | big-iq_application_delivery_controller |
| f5 | big-iq_centralized_management |
| f5 | big-iq_cloud · 4.0.0 → 4.5.0 |
| f5 | big-iq_cloud_and_orchestration |
| f5 | big-iq_device · 4.2.0 → 4.5.0 |
| f5 | big-iq_security · 4.0.0 → 4.5.0 |
| f5 | enterprise_manager |
| linux | linux_kernel |
| linux | linux_kernel · 2.6.31 → 3.2.59 |
| linux | linux_kernel · 3.11 → 3.12.20 |
| linux | linux_kernel · 3.13 → 3.14.4 |
| linux | linux_kernel · 3.3 → 3.4.91 |
| linux | linux_kernel · 3.5 → 3.10.40 |
| oracle | linux |
| redhat | enterprise_linux |
| redhat | enterprise_linux_eus |
| redhat | enterprise_linux_server_eus |
| suse | suse_linux_enterprise_desktop |
| suse | suse_linux_enterprise_high_availability_extension |
| suse | suse_linux_enterprise_server |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.