3.3

CVE-2014-3917

kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, allows local users to obtain potentially sensitive single-bit values from kernel memory or cause a denial of service (OOPS) via a large value of a syscall number.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Suse ≫ Linux Enterprise Desktop Version 10.0 Update sp4 SwEdition lts
Redhat ≫ Enterprise Linux Version 5
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Mrg Version 2.0
Linux ≫ Linux Kernel Version <= 3.14.5
Linux ≫ Linux Kernel Version 3.14 Update -
Linux ≫ Linux Kernel Version 3.14 Update rc1
Linux ≫ Linux Kernel Version 3.14 Update rc2
Linux ≫ Linux Kernel Version 3.14 Update rc3
Linux ≫ Linux Kernel Version 3.14 Update rc4
Linux ≫ Linux Kernel Version 3.14 Update rc5
Linux ≫ Linux Kernel Version 3.14 Update rc6
Linux ≫ Linux Kernel Version 3.14 Update rc7
Linux ≫ Linux Kernel Version 3.14 Update rc8
Linux ≫ Linux Kernel Version 3.14.1
Linux ≫ Linux Kernel Version 3.14.2
Linux ≫ Linux Kernel Version 3.14.3
Linux ≫ Linux Kernel Version 3.14.4
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.276
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.3 3.4 4.9
AV:L/AC:M/Au:N/C:P/I:N/A:P
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html
http://article.gmane.org/gmane.linux.kernel/1713179
http://rhn.redhat.com/errata/RHSA-2014-1143.html
http://rhn.redhat.com/errata/RHSA-2014-1281.html
http://secunia.com/advisories/59777
http://secunia.com/advisories/60011
http://secunia.com/advisories/60564
http://www.openwall.com/lists/oss-security/2014/05/29/5
http://www.ubuntu.com/usn/USN-2334-1
http://www.ubuntu.com/usn/USN-2335-1
https://bugzilla.redhat.com/show_bug.cgi?id=1102571