2.1

CVE-2013-2148

The fill_event_metadata function in fs/notify/fanotify/fanotify_user.c in the Linux kernel through 3.9.4 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a read operation on the fanotify descriptor.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version <= 3.9.4
Linux ≫ Linux Kernel Version 3.9 Update rc1
Linux ≫ Linux Kernel Version 3.9 Update rc2
Linux ≫ Linux Kernel Version 3.9 Update rc3
Linux ≫ Linux Kernel Version 3.9 Update rc4
Linux ≫ Linux Kernel Version 3.9 Update rc5
Linux ≫ Linux Kernel Version 3.9 Update rc6
Linux ≫ Linux Kernel Version 3.9 Update rc7
Linux ≫ Linux Kernel Version 3.9.0
Linux ≫ Linux Kernel Version 3.9.1
Linux ≫ Linux Kernel Version 3.9.2
Linux ≫ Linux Kernel Version 3.9.3
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.276
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.html
http://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html
http://lkml.org/lkml/2013/6/3/128
http://www.openwall.com/lists/oss-security/2013/06/05/26
http://www.ubuntu.com/usn/USN-1929-1
http://www.ubuntu.com/usn/USN-1930-1
https://bugzilla.redhat.com/show_bug.cgi?id=971258