2.1

CVE-2010-2955

The cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the Linux kernel before 2.6.36-rc3-next-20100831 does not properly initialize certain structure members, which allows local users to leverage an off-by-one error in the ioctl_standard_iw_point function in net/wireless/wext-core.c, and obtain potentially sensitive information from kernel heap memory, via vectors involving an SIOCGIWESSID ioctl call that specifies a large buffer size.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version < 2.6.36
LinuxLinux Kernel Version2.6.36 Update-
LinuxLinux Kernel Version2.6.36 Updaterc1
LinuxLinux Kernel Version2.6.36 Updaterc2
OpensuseOpensuse Version11.1
SuseLinux Enterprise Desktop Version11 Update-
SuseLinux Enterprise Real Time Extension Version11 Updatesp1
SuseLinux Enterprise Server Version11 Update-
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version8.04 SwEdition-
CanonicalUbuntu Linux Version9.04
CanonicalUbuntu Linux Version9.10
CanonicalUbuntu Linux Version10.04 SwEdition-
CanonicalUbuntu Linux Version10.10
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.259
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-193 Off-by-one Error

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

http://lkml.org/lkml/2010/8/27/413
Patch
Third Party Advisory
Mailing List
http://lkml.org/lkml/2010/8/30/127
Patch
Third Party Advisory
Mailing List
http://lkml.org/lkml/2010/8/30/146
Patch
Third Party Advisory
Mailing List
http://lkml.org/lkml/2010/8/30/351
Patch
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2010/08/31/1
Patch
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/42885
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=628434
Third Party Advisory
Issue Tracking