1.9
CVE-2010-4525
- EPSS 0.34%
- Veröffentlicht 11.01.2011 03:00:04
- Zuletzt bearbeitet 16.06.2026 23:24:58
- CVE-Watchlists
- Unerledigt
Linux kernel 2.6.33 and 2.6.34.y does not initialize the kvm_vcpu_events->interrupt.pad structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version2.6.33
Linux ≫ Linux Kernel Version2.6.34
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.257 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 1.9 | 3.4 | 2.9 |
AV:L/AC:M/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://secunia.com/advisories/42890
http://www.redhat.com/support/errata/RHSA-2011-0007.html
http://osvdb.org/70377
http://www.openwall.com/lists/oss-security/2011/01/05/1
http://www.openwall.com/lists/oss-security/2011/01/05/9
http://www.openwall.com/lists/oss-security/2011/01/06/3
http://www.redhat.com/support/errata/RHSA-2011-0028.html
http://www.securityfocus.com/bid/45676
http://www.vupen.com/english/advisories/2011/0123
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4525
https://exchange.xforce.ibmcloud.com/vulnerabilities/64519