6.5
CVE-2019-3460
- EPSS 1.83%
- Veröffentlicht 11.04.2019 16:29:02
- Zuletzt bearbeitet 21.11.2024 04:42:05
- Erkennungen
A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version <= 5.1
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.10
Debian ≫ Debian Linux Version 8.0
Redhat ≫ Codeready Linux Builder Version 8.0
Redhat ≫ Virtualization Host Version 4.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Eus Version 8.1
Redhat ≫ Enterprise Linux Eus Version 8.2
Redhat ≫ Enterprise Linux Eus Version 8.4
Redhat ≫ Enterprise Linux For Real Time Version 7
Redhat ≫ Enterprise Linux For Real Time Version 8
Redhat ≫ Enterprise Linux For Real Time For Nfv Version 7
Redhat ≫ Enterprise Linux For Real Time For Nfv Version 8
Redhat ≫ Enterprise Linux For Real Time For Nfv Tus Version 8.2
Redhat ≫ Enterprise Linux For Real Time For Nfv Tus Version 8.4
Redhat ≫ Enterprise Linux For Real Time Tus Version 8.2
Redhat ≫ Enterprise Linux For Real Time Tus Version 8.4
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Aus Version 8.2
Redhat ≫ Enterprise Linux Server Aus Version 8.4
Redhat ≫ Enterprise Linux Server Tus Version 8.2
Redhat ≫ Enterprise Linux Server Tus Version 8.4
Redhat ≫ Enterprise Linux Workstation Version 7.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.83% | 0.76 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 3.3 | 6.5 | 2.9 |
AV:A/AC:L/Au:N/C:P/I:N/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://access.redhat.com/errata/RHSA-2019:3517
http://www.openwall.com/lists/oss-security/2019/06/27/7
http://www.openwall.com/lists/oss-security/2019/06/28/1
http://www.openwall.com/lists/oss-security/2019/06/28/2
https://lists.debian.org/debian-lts-announce/2019/05/msg00002.html
https://access.redhat.com/errata/RHSA-2019:2029
https://access.redhat.com/errata/RHSA-2019:2043
https://lists.debian.org/debian-lts-announce/2019/05/msg00041.html
https://lists.debian.org/debian-lts-announce/2019/05/msg00042.html
https://access.redhat.com/errata/RHSA-2019:3309
http://www.openwall.com/lists/oss-security/2019/06/27/2
http://www.openwall.com/lists/oss-security/2019/08/12/1
https://access.redhat.com/errata/RHSA-2020:0740
https://marc.info/?l=oss-security&m=154721580222522&w=2
https://bugzilla.redhat.com/show_bug.cgi?id=1663179
https://git.kernel.org/linus/af3d5d1c87664a4f150fcf3534c6567cb19909b0
https://lore.kernel.org/linux-bluetooth/20190110062917.GB15047%40kroah.com/
https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-3460.html