2.1

CVE-2010-3881

arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device.

Data is provided by the National Vulnerability Database (NVD)
LinuxLinux Kernel Version < 2.6.36.2
SuseSuse Linux Enterprise Desktop Version11 Updatesp1
SuseSuse Linux Enterprise Server Version11 Updatesp1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.193
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://openwall.com/lists/oss-security/2010/11/04/10
Patch
Third Party Advisory
Mailing List
http://openwall.com/lists/oss-security/2010/11/05/4
Patch
Third Party Advisory
Mailing List
http://securitytracker.com/id?1024912
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/44666
Patch
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=649920
Patch
Third Party Advisory
Issue Tracking