2.1
CVE-2010-1636
- EPSS 0.24%
- Veröffentlicht 08.06.2010 00:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle secalert@redhat.com
- Teams Watchlist Login
- Unerledigt Login
The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the btrfs functionality in the Linux kernel 2.6.29 through 2.6.32, and possibly other versions, does not ensure that a cloned file descriptor has been opened for reading, which allows local users to read sensitive information from a write-only file descriptor.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version2.6.29
Linux ≫ Linux Kernel Version2.6.29.1
Linux ≫ Linux Kernel Version2.6.29.2
Linux ≫ Linux Kernel Version2.6.29.3
Linux ≫ Linux Kernel Version2.6.29.4
Linux ≫ Linux Kernel Version2.6.29.5
Linux ≫ Linux Kernel Version2.6.29.6
Linux ≫ Linux Kernel Version2.6.30
Linux ≫ Linux Kernel Version2.6.30.1
Linux ≫ Linux Kernel Version2.6.30.2
Linux ≫ Linux Kernel Version2.6.30.3
Linux ≫ Linux Kernel Version2.6.30.4
Linux ≫ Linux Kernel Version2.6.30.5
Linux ≫ Linux Kernel Version2.6.30.6
Linux ≫ Linux Kernel Version2.6.30.7
Linux ≫ Linux Kernel Version2.6.30.8
Linux ≫ Linux Kernel Version2.6.30.9
Linux ≫ Linux Kernel Version2.6.30.10
Linux ≫ Linux Kernel Version2.6.31
Linux ≫ Linux Kernel Version2.6.31.1
Linux ≫ Linux Kernel Version2.6.31.2
Linux ≫ Linux Kernel Version2.6.31.3
Linux ≫ Linux Kernel Version2.6.31.4
Linux ≫ Linux Kernel Version2.6.31.5
Linux ≫ Linux Kernel Version2.6.31.6
Linux ≫ Linux Kernel Version2.6.31.7
Linux ≫ Linux Kernel Version2.6.31.8
Linux ≫ Linux Kernel Version2.6.31.9
Linux ≫ Linux Kernel Version2.6.31.10
Linux ≫ Linux Kernel Version2.6.31.11
Linux ≫ Linux Kernel Version2.6.31.12
Linux ≫ Linux Kernel Version2.6.31.13
Linux ≫ Linux Kernel Version2.6.32
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.24% | 0.476 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.