ID

VAR-E-200410-0228


CVE

cve_id:CVE-2004-0834

Trust: 0.3

sources: BID: 11496

TITLE

Speedtouch USB Driver Local Format String Vulnerability

Trust: 0.3

sources: BID: 11496

DESCRIPTION

Speedtouch USB Driver is prone to a locally exploitable format string vulnerability. The problem occurs due to insufficient sanitization of user-supplied data.
This vulnerability may be exploited in order to have arbitrary code executed with superuser privileges.

Trust: 0.3

sources: BID: 11496

AFFECTED PRODUCTS

vendor:speedtouchmodel:usb driver speedtouch usb driverscope:eqversion:1.3

Trust: 0.3

vendor:speedtouchmodel:usb driver speedtouch usb driver beta3scope:eqversion:1.2

Trust: 0.3

vendor:speedtouchmodel:usb driver speedtouch usb driver beta2scope:eqversion:1.2

Trust: 0.3

vendor:speedtouchmodel:usb driver speedtouch usb driver beta1scope:eqversion:1.2

Trust: 0.3

vendor:speedtouchmodel:usb driver speedtouch usb driverscope:eqversion:1.2

Trust: 0.3

vendor:speedtouchmodel:usb driver speedtouch usb driverscope:eqversion:1.1

Trust: 0.3

vendor:speedtouchmodel:usb driver speedtouch usb driverscope:eqversion:1.0

Trust: 0.3

vendor:mandrivamodel:linux mandrake x86 64scope:eqversion:10.1

Trust: 0.3

vendor:mandrivamodel:linux mandrakescope:eqversion:10.1

Trust: 0.3

vendor:mandrivamodel:linux mandrake amd64scope:eqversion:10.0

Trust: 0.3

vendor:mandrivamodel:linux mandrakescope:eqversion:10.0

Trust: 0.3

vendor:mandrivamodel:linux mandrake amd64scope:eqversion:9.2

Trust: 0.3

vendor:mandrivamodel:linux mandrakescope:eqversion:9.2

Trust: 0.3

vendor:mandrivamodel:linux mandrake ppcscope:eqversion:9.1

Trust: 0.3

vendor:mandrivamodel:linux mandrakescope:eqversion:9.1

Trust: 0.3

vendor:mandrivamodel:linux mandrakescope:eqversion:9.0

Trust: 0.3

vendor:mandrivamodel:linux mandrake ppcscope:eqversion:8.2

Trust: 0.3

vendor:mandrivamodel:linux mandrakescope:eqversion:8.2

Trust: 0.3

vendor:mandrakesoftmodel:multi network firewallscope:eqversion:2.0

Trust: 0.3

vendor:mandrakesoftmodel:corporate server x86 64scope:eqversion:2.1

Trust: 0.3

vendor:mandrakesoftmodel:corporate serverscope:eqversion:2.1

Trust: 0.3

vendor:gentoomodel:linuxscope:eqversion:1.4

Trust: 0.3

vendor:gentoomodel:linuxscope: - version: -

Trust: 0.3

vendor:speedtouchmodel:usb driver speedtouch usb driverscope:neversion:1.3.1

Trust: 0.3

sources: BID: 11496

EXPLOIT

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com <mailto:vuldb@securityfocus.com>.

Trust: 0.3

sources: BID: 11496

PRICE

Free

Trust: 0.3

sources: BID: 11496

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 11496

CREDITS

Discovery is credited to Max Vozeler.

Trust: 0.3

sources: BID: 11496

EXTERNAL IDS

db:NVDid:CVE-2004-0834

Trust: 0.3

db:BIDid:11496

Trust: 0.3

sources: BID: 11496

REFERENCES

url:http://speedtouch.sourceforge.net/

Trust: 0.3

sources: BID: 11496

SOURCES

db:BIDid:11496

LAST UPDATE DATE

2022-07-27T09:29:07.498000+00:00


SOURCES UPDATE DATE

db:BIDid:11496date:2009-07-12T08:06:00

SOURCES RELEASE DATE

db:BIDid:11496date:2004-10-21T00:00:00