Multiple stack-based buffer overflows in the iriap_getvaluebyclass_indication function in net/irda/iriap.c in the Linux kernel before 2.6.39 allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging connectivity to an IrDA infrared network and sending a large integer value for a (1) name length or (2) attribute length.
| Product | Vendor | Version |
|---|---|---|
| n/a | n/a | < a84b4afaca2573ed3aed1f8854aefe3ca5a82e72 |