5.5
CVE-2016-4569
- EPSS 0.37%
- Veröffentlicht 23.05.2016 10:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version <= 4.6
Canonical ≫ Ubuntu Linux Version12.04 SwEditionlts
Canonical ≫ Ubuntu Linux Version14.04 SwEditionlts
Canonical ≫ Ubuntu Linux Version15.10
Canonical ≫ Ubuntu Linux Version16.04 SwEditionlts
Novell ≫ Suse Linux Enterprise Software Development Kit Version11.0 Updatesp4
Novell ≫ Suse Linux Enterprise Software Development Kit Version12.0
Novell ≫ Suse Linux Enterprise Software Development Kit Version12.0 Updatesp1
Novell ≫ Suse Linux Enterprise Debuginfo Version11.0 Updatesp4
Novell ≫ Suse Linux Enterprise Desktop Version12.0
Novell ≫ Suse Linux Enterprise Desktop Version12.0 Updatesp1
Novell ≫ Suse Linux Enterprise Live Patching Version12.0
Novell ≫ Suse Linux Enterprise Module For Public Cloud Version12.0
Novell ≫ Suse Linux Enterprise Real Time Extension Version12.0 Updatesp1
Novell ≫ Suse Linux Enterprise Server Version11.0 Updateextra
Novell ≫ Suse Linux Enterprise Server Version11.0 Updatesp4
Novell ≫ Suse Linux Enterprise Server Version12.0
Novell ≫ Suse Linux Enterprise Server Version12.0 Updatesp1
Novell ≫ Suse Linux Enterprise Workstation Extension Version12.0
Novell ≫ Suse Linux Enterprise Workstation Extension Version12.0 Updatesp1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.37% | 0.58 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.