2.1
CVE-2012-3430
- EPSS 0.27%
- Veröffentlicht 03.10.2012 11:02:56
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle secalert@redhat.com
- Teams Watchlist Login
- Unerledigt Login
The rds_recvmsg function in net/rds/recv.c in the Linux kernel before 3.0.44 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) recvfrom or (2) recvmsg system call on an RDS socket.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version <= 3.0.43
Linux ≫ Linux Kernel Version3.0.1
Linux ≫ Linux Kernel Version3.0.2
Linux ≫ Linux Kernel Version3.0.3
Linux ≫ Linux Kernel Version3.0.4
Linux ≫ Linux Kernel Version3.0.5
Linux ≫ Linux Kernel Version3.0.6
Linux ≫ Linux Kernel Version3.0.7
Linux ≫ Linux Kernel Version3.0.8
Linux ≫ Linux Kernel Version3.0.9
Linux ≫ Linux Kernel Version3.0.10
Linux ≫ Linux Kernel Version3.0.11
Linux ≫ Linux Kernel Version3.0.12
Linux ≫ Linux Kernel Version3.0.13
Linux ≫ Linux Kernel Version3.0.14
Linux ≫ Linux Kernel Version3.0.15
Linux ≫ Linux Kernel Version3.0.16
Linux ≫ Linux Kernel Version3.0.17
Linux ≫ Linux Kernel Version3.0.18
Linux ≫ Linux Kernel Version3.0.19
Linux ≫ Linux Kernel Version3.0.20
Linux ≫ Linux Kernel Version3.0.21
Linux ≫ Linux Kernel Version3.0.22
Linux ≫ Linux Kernel Version3.0.23
Linux ≫ Linux Kernel Version3.0.24
Linux ≫ Linux Kernel Version3.0.25
Linux ≫ Linux Kernel Version3.0.26
Linux ≫ Linux Kernel Version3.0.27
Linux ≫ Linux Kernel Version3.0.28
Linux ≫ Linux Kernel Version3.0.29
Linux ≫ Linux Kernel Version3.0.30
Linux ≫ Linux Kernel Version3.0.31
Linux ≫ Linux Kernel Version3.0.32
Linux ≫ Linux Kernel Version3.0.33
Linux ≫ Linux Kernel Version3.0.34
Linux ≫ Linux Kernel Version3.0.35
Linux ≫ Linux Kernel Version3.0.36
Linux ≫ Linux Kernel Version3.0.37
Linux ≫ Linux Kernel Version3.0.38
Linux ≫ Linux Kernel Version3.0.39
Linux ≫ Linux Kernel Version3.0.40
Linux ≫ Linux Kernel Version3.0.41
Linux ≫ Linux Kernel Version3.0.42
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.27% | 0.502 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.