1.9
CVE-2010-4072
- EPSS 0.38%
- Veröffentlicht 29.11.2010 16:00:02
- Zuletzt bearbeitet 16.06.2026 23:24:04
- Erkennungen
The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the shmctl system call and the "old shm interface."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 2.6.37
Linux ≫ Linux Kernel Version 2.6.37 Update -
Suse ≫ Linux Enterprise Desktop Version 10 Update sp3
Suse ≫ Linux Enterprise Desktop Version 11 Update sp1
Suse ≫ Linux Enterprise Real Time Extension Version 11 Update sp1
Suse ≫ Linux Enterprise Server Version 9
Suse ≫ Linux Enterprise Server Version 10 Update sp3
Suse ≫ Linux Enterprise Server Version 11 Update sp1
Suse ≫ Linux Enterprise Software Development Kit Version 10 Update sp3
Debian ≫ Debian Linux Version 5.0
Canonical ≫ Ubuntu Linux Version 6.06
Canonical ≫ Ubuntu Linux Version 9.10
Canonical ≫ Ubuntu Linux Version 10.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 10.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.38% | 0.3 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 1.9 | 3.4 | 2.9 |
AV:L/AC:M/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://www.mandriva.com/security/advisories?name=MDVSA-2011:051
http://www.mandriva.com/security/advisories?name=MDVSA-2011:029
http://secunia.com/advisories/46397
http://www.securityfocus.com/archive/1/520102/100/0/threaded
http://www.vmware.com/security/advisories/VMSA-2011-0012.html
http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html
http://www.vupen.com/english/advisories/2011/0298
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html
http://secunia.com/advisories/42778
http://www.vupen.com/english/advisories/2011/0012
http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00004.html
http://secunia.com/advisories/42890
http://www.redhat.com/support/errata/RHSA-2011-0007.html
http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.html
http://secunia.com/advisories/43291
http://www.debian.org/security/2010/dsa-2126
http://www.vupen.com/english/advisories/2011/0375
http://secunia.com/advisories/42758
http://www.ubuntu.com/usn/USN-1041-1
http://www.vupen.com/english/advisories/2011/0070
http://secunia.com/advisories/43161
http://www.ubuntu.com/usn/USN-1057-1
http://www.vupen.com/english/advisories/2011/0280
http://secunia.com/advisories/42884
http://www.redhat.com/support/errata/RHSA-2011-0017.html
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00004.html
http://secunia.com/advisories/42932
http://www.vupen.com/english/advisories/2011/0124
http://www.redhat.com/support/errata/RHSA-2010-0958.html
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3af54c9bd9e6f14f896aac1bb0e8405ae0bc7a44
http://lkml.org/lkml/2010/10/6/454
http://secunia.com/advisories/42963
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc1
http://www.openwall.com/lists/oss-security/2010/10/07/1
http://www.openwall.com/lists/oss-security/2010/10/25/3
http://www.redhat.com/support/errata/RHSA-2011-0162.html
http://www.securityfocus.com/bid/45054
http://www.vupen.com/english/advisories/2011/0168
https://bugzilla.redhat.com/show_bug.cgi?id=648656