1.2

CVE-2012-2313

Exploit

The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.

Data is provided by the National Vulnerability Database (NVD)
LinuxLinux Kernel Version <= 3.3.6
LinuxLinux Kernel Version3.3
LinuxLinux Kernel Version3.3 Updaterc1
LinuxLinux Kernel Version3.3 Updaterc2
LinuxLinux Kernel Version3.3 Updaterc3
LinuxLinux Kernel Version3.3 Updaterc4
LinuxLinux Kernel Version3.3 Updaterc5
LinuxLinux Kernel Version3.3 Updaterc6
LinuxLinux Kernel Version3.3 Updaterc7
LinuxLinux Kernel Version3.3.1
LinuxLinux Kernel Version3.3.2
LinuxLinux Kernel Version3.3.3
LinuxLinux Kernel Version3.3.4
LinuxLinux Kernel Version3.3.5
NovellSuse Linux Enterprise Server Version10.0 Updatesp4 SwEditionltss
RedhatEnterprise Linux Version5 Editionserver
RedhatEnterprise Linux Desktop Version5.0 Editionclient
RedhatEnterprise Linux Eus Version5.6.z Editionserver
RedhatEnterprise Linux Long Life Version5.6 Editionserver
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.22% 0.451
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 1.2 1.9 2.9
AV:L/AC:H/Au:N/C:N/I:N/A:P