An exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadySHARE Printer functionality of at least two NETGEAR Nighthawk Routers and potentially several other vendors/products. A specially crafted index value can cause an invalid memory read, resulting in a denial of service or remote information disclosure. An unauthenticated attacker can send a crafted packet on the local network to trigger this vulnerability.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/108820 | Broken Link |
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0775 | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
|
History
13 Jun 2022, 18:40
Type | Values Removed | Values Added |
---|---|---|
References | (BID) http://www.securityfocus.com/bid/108820 - Broken Link |
Information
Published : 2019-06-17 21:15
Updated : 2024-02-04 20:20
NVD link : CVE-2019-5016
Mitre link : CVE-2019-5016
CVE.ORG link : CVE-2019-5016
JSON object : View
Products Affected
netgear
- r8000
- r7900_firmware
- r8000_firmware
- r7900
kcodes
- netusb.ko
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor