2.1

CVE-2013-2141

Exploit

The do_tkill function in kernel/signal.c in the Linux kernel before 3.8.9 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via a crafted application that makes a (1) tkill or (2) tgkill system call.

Data is provided by the National Vulnerability Database (NVD)
LinuxLinux Kernel Version <= 3.8.8
LinuxLinux Kernel Version3.8.0
LinuxLinux Kernel Version3.8.1
LinuxLinux Kernel Version3.8.2
LinuxLinux Kernel Version3.8.3
LinuxLinux Kernel Version3.8.4
LinuxLinux Kernel Version3.8.5
LinuxLinux Kernel Version3.8.6
LinuxLinux Kernel Version3.8.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.102
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N