2.1

CVE-2014-9585

Exploit
The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end of a PMD.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version <= 3.18.2
Redhat ≫ Enterprise Linux Aus Version 6.6
Redhat ≫ Enterprise Linux Eus Version 6.6
Opensuse ≫ Evergreen Version 11.4
Opensuse ≫ Opensuse Version 13.1
Suse ≫ Linux Enterprise Desktop Version 12 Update -
Suse ≫ Linux Enterprise Real Time Extension Version 11 Update sp3
Suse ≫ Linux Enterprise Server Version 11 Update sp1 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp2 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 12 Update -
Fedoraproject ≫ Fedora Version 21
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.10
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.56% 0.42
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html
Third Party Advisory
Mailing List
http://www.ubuntu.com/usn/USN-2513-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2514-1
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00035.html
Third Party Advisory
Mailing List
http://www.mandriva.com/security/advisories?name=MDVSA-2015:058
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00009.html
Third Party Advisory
Mailing List
http://www.debian.org/security/2015/dsa-3170
Third Party Advisory
http://www.ubuntu.com/usn/USN-2515-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2516-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2517-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2518-1
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1081.html
Third Party Advisory
http://git.kernel.org/?p=linux/kernel/git/luto/linux.git%3Ba=commit%3Bh=bc3b94c31d65e761ddfe150d02932c65971b74e2
http://git.kernel.org/?p=linux/kernel/git/tip/tip.git%3Ba=commit%3Bh=fbe1bf140671619508dfa575d74a185ae53c5dbb
http://lists.fedoraproject.org/pipermail/package-announce/2015-January/148480.html
Third Party Advisory
Mailing List
http://rhn.redhat.com/errata/RHSA-2015-1778.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1787.html
Third Party Advisory
http://v0ids3curity.blogspot.in/2014/12/return-to-vdso-using-elf-auxiliary.html
Broken Link
http://www.openwall.com/lists/oss-security/2014/12/09/10
Third Party Advisory
Exploit
Mailing List
http://www.openwall.com/lists/oss-security/2015/01/09/8
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/71990
Third Party Advisory
VDB Entry