CVE-2006-0457 | Date: (C)2006-03-13 (M)2023-12-22 |
Race condition in the (1) add_key, (2) request_key, and (3) keyctl functions in Linux kernel 2.6.x allows local users to cause a denial of service (crash) or read sensitive kernel memory by modifying the length of a string argument between the time that the kernel calculates the length and when it copies the data into kernel memory.
CVSS Score and Metrics +CVSS Score and Metrics -CVSS V2 Severity: |
CVSS Score : 7.1 |
Exploit Score: 4.9 |
Impact Score: 9.2 |
|
CVSS V2 Metrics: |
Access Vector: NETWORK |
Access Complexity: HIGH |
Authentication: NONE |
Confidentiality: COMPLETE |
Integrity: NONE |
Availability: COMPLETE |
| |