Automated analysis has detected that the following third party packages have had vulnerabilities publicly reported.
NOTE: There may be several bugs listed below - in almost all cases, all bugs can be quickly addressed by upgrading to the latest version of the package.
Package Name: sys-kernel/chromeos-kernel-4_4
Package Version: [cpe:/o:linux:linux_kernel:4.4.79]
Advisory: CVE-2017-12762
Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-2017-12762
CVSS severity score: 10/10.0
Confidence: high
Description:
In /drivers/isdn/i4l/isdn_net.c: A user-controlled buffer is copied into a local buffer of constant size using strcpy without a length check which can cause a buffer overflow. This affects the Linux kernel 4.9-stable tree, 4.12-stable tree, 3.18-stable tree, and 4.4-stable tree.
Comment 1 by ta...@google.com
, Aug 28 2017Labels: Security_Severity-Medium Security_Impact-Stable
Owner: groeck@chromium.org
Status: Assigned (was: Untriaged)