5.5
CVE-2016-4569
- EPSS 0.84%
- Veröffentlicht 23.05.2016 10:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version <= 4.6
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 15.10
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Novell ≫ Suse Linux Enterprise Software Development Kit Version 11.0 Update sp4
Novell ≫ Suse Linux Enterprise Software Development Kit Version 12.0
Novell ≫ Suse Linux Enterprise Software Development Kit Version 12.0 Update sp1
Novell ≫ Suse Linux Enterprise Debuginfo Version 11.0 Update sp4
Novell ≫ Suse Linux Enterprise Desktop Version 12.0
Novell ≫ Suse Linux Enterprise Desktop Version 12.0 Update sp1
Novell ≫ Suse Linux Enterprise Live Patching Version 12.0
Novell ≫ Suse Linux Enterprise Module For Public Cloud Version 12.0
Novell ≫ Suse Linux Enterprise Real Time Extension Version 12.0 Update sp1
Novell ≫ Suse Linux Enterprise Server Version 11.0 Update extra
Novell ≫ Suse Linux Enterprise Server Version 11.0 Update sp4
Novell ≫ Suse Linux Enterprise Server Version 12.0
Novell ≫ Suse Linux Enterprise Server Version 12.0 Update sp1
Novell ≫ Suse Linux Enterprise Workstation Extension Version 12.0
Novell ≫ Suse Linux Enterprise Workstation Extension Version 12.0 Update sp1
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.84% | 0.533 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.html
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.html
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.html
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00044.html
http://rhn.redhat.com/errata/RHSA-2016-2574.html
http://rhn.redhat.com/errata/RHSA-2016-2584.html
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html
http://www.debian.org/security/2016/dsa-3607
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00056.html
http://www.ubuntu.com/usn/USN-3021-1
http://www.ubuntu.com/usn/USN-3021-2
http://www.ubuntu.com/usn/USN-3016-1
http://www.ubuntu.com/usn/USN-3016-2
http://www.ubuntu.com/usn/USN-3016-3
http://www.ubuntu.com/usn/USN-3016-4
http://www.ubuntu.com/usn/USN-3017-1
http://www.ubuntu.com/usn/USN-3017-2
http://www.ubuntu.com/usn/USN-3017-3
http://www.ubuntu.com/usn/USN-3018-1
http://www.ubuntu.com/usn/USN-3018-2
http://www.ubuntu.com/usn/USN-3019-1
http://www.ubuntu.com/usn/USN-3020-1
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cec8f96e49d9be372fdb0c3836dcf31ec71e457e
http://www.openwall.com/lists/oss-security/2016/05/09/17
http://www.securityfocus.com/bid/90347
https://bugzilla.redhat.com/show_bug.cgi?id=1334643
https://github.com/torvalds/linux/commit/cec8f96e49d9be372fdb0c3836dcf31ec71e457e