6.2

CVE-2016-4482

The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 15.10
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Linux ≫ Linux Kernel Version <= 4.6
Novell ≫ Suse Linux Enterprise Debuginfo Version 11.0 Update sp4
Novell ≫ Suse Linux Enterprise Desktop Version 12.0 Update sp1
Novell ≫ Suse Linux Enterprise Server Version 11.0 Update extra
Novell ≫ Suse Linux Enterprise Server Version 11.0 Update sp4
Novell ≫ Suse Linux Enterprise Server Version 12.0 Update sp1
Fedoraproject ≫ Fedora Version 24
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.55% 0.417
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.2 2.5 3.6
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.html
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.html
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.html
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00044.html
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html
Third Party Advisory
http://www.debian.org/security/2016/dsa-3607
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00056.html
Third Party Advisory
http://www.ubuntu.com/usn/USN-3021-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-3021-2
Third Party Advisory
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=681fef8380eb818c0b845fca5d2ab1dcbab114ee
Vendor Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184414.html
http://www.openwall.com/lists/oss-security/2016/05/04/2
http://www.securityfocus.com/bid/90029
http://www.ubuntu.com/usn/USN-3016-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-3016-2
Third Party Advisory
http://www.ubuntu.com/usn/USN-3016-3
Third Party Advisory
http://www.ubuntu.com/usn/USN-3016-4
Third Party Advisory
http://www.ubuntu.com/usn/USN-3017-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-3017-2
Third Party Advisory
http://www.ubuntu.com/usn/USN-3017-3
Third Party Advisory
http://www.ubuntu.com/usn/USN-3018-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-3018-2
Third Party Advisory
http://www.ubuntu.com/usn/USN-3019-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-3020-1
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1332931
Issue Tracking
https://github.com/torvalds/linux/commit/681fef8380eb818c0b845fca5d2ab1dcbab114ee
Vendor Advisory