In FreeBSD 12.1-STABLE before r362166, 12.1-RELEASE before p8, 11.4-STABLE before r362167, 11.4-RELEASE before p2, and 11.3-RELEASE before p12, missing length validation code common to mulitple USB network drivers allows a malicious USB device to write beyond the end of an allocated network packet buffer.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-28585 In FreeBSD 12.1-STABLE before r362166, 12.1-RELEASE before p8, 11.4-STABLE before r362167, 11.4-RELEASE before p2, and 11.3-RELEASE before p12, missing length validation code common to mulitple USB network drivers allows a malicious USB device to write beyond the end of an allocated network packet buffer.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: freebsd

Published:

Updated: 2024-08-04T09:25:49.099Z

Reserved: 2020-01-21T00:00:00

Link: CVE-2020-7459

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-08-06T17:15:11.253

Modified: 2024-11-21T05:37:11.223

Link: CVE-2020-7459

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.