The Orinoco driver (orinoco.c) in Linux kernel 2.6.13 and earlier does not properly clear memory from a previously used packet whose length is increased, which allows remote attackers to obtain sensitive information.

Project Subscriptions

Vendors Products
Linux Kernel Subscribe
Enterprise Linux Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-1017-1 New Linux kernel 2.6.8 packages fix several vulnerabilities
EUVD EUVD EUVD-2005-3179 The Orinoco driver (orinoco.c) in Linux kernel 2.6.13 and earlier does not properly clear memory from a previously used packet whose length is increased, which allows remote attackers to obtain sensitive information.
Ubuntu USN Ubuntu USN USN-219-1 Linux kernel vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://marc.info/?l=bugtraq&m=112914754708402&w=2 cve-icon cve-icon
http://secunia.com/advisories/17114 cve-icon cve-icon
http://secunia.com/advisories/17280 cve-icon cve-icon
http://secunia.com/advisories/17364 cve-icon cve-icon
http://secunia.com/advisories/17826 cve-icon cve-icon
http://secunia.com/advisories/17917 cve-icon cve-icon
http://secunia.com/advisories/17918 cve-icon cve-icon
http://secunia.com/advisories/18562 cve-icon cve-icon
http://secunia.com/advisories/18684 cve-icon cve-icon
http://secunia.com/advisories/19374 cve-icon cve-icon
http://securityreason.com/securityalert/75 cve-icon cve-icon
http://www.debian.org/security/2006/dsa-1017 cve-icon cve-icon
http://www.kernel.org/hg/linux-2.6/?cmd=changeset%3Bnode=feecb2ffde28639e60ede769c6f817dc536c677b cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2005:218 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2005:219 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2005:220 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2005:235 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2005-808.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2006-0140.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2006-0190.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2006-0191.html cve-icon cve-icon
http://www.securityfocus.com/advisories/9549 cve-icon cve-icon
http://www.securityfocus.com/advisories/9806 cve-icon cve-icon
http://www.securityfocus.com/archive/1/419522/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/427980/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/428028/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/428058/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/15085 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2005-3180 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11332 cve-icon cve-icon
https://usn.ubuntu.com/219-1/ cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2005-3180 cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T23:01:59.272Z

Reserved: 2005-10-11T00:00:00

Link: CVE-2005-3180

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2005-10-12T13:04:00.000

Modified: 2025-04-03T01:03:51.193

Link: CVE-2005-3180

cve-icon Redhat

Severity : Important

Publid Date: 2005-10-04T00:00:00Z

Links: CVE-2005-3180 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses