7.2

CVE-2009-3080

Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.

Data is provided by the National Vulnerability Database (NVD)
LinuxLinux Kernel Version <= 2.6.31.6
LinuxLinux Kernel Version2.6.32 Update-
LinuxLinux Kernel Version2.6.32 Updaterc1
LinuxLinux Kernel Version2.6.32 Updaterc3
LinuxLinux Kernel Version2.6.32 Updaterc4
LinuxLinux Kernel Version2.6.32 Updaterc5
OpensuseOpensuse Version11.1
OpensuseOpensuse Version11.2
SuseLinux Enterprise Desktop Version10 Updatesp2
SuseLinux Enterprise Desktop Version10 Updatesp3
SuseLinux Enterprise Server Version10 Updatesp2 SwEdition-
SuseLinux Enterprise Server Version10 Updatesp3 SwEdition-
DebianDebian Linux Version4.0
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version8.04
CanonicalUbuntu Linux Version8.10
CanonicalUbuntu Linux Version9.04
CanonicalUbuntu Linux Version9.10
VMwareEsx Version3.5
RedhatVirtualization Version5.0
RedhatEnterprise Linux Eus Version5.4
RedhatFedora Version10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.185
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-129 Improper Validation of Array Index

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

http://www.securityfocus.com/bid/37068
Third Party Advisory
VDB Entry