[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-4072Date: (C)2010-11-29   (M)2024-02-22


The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the shmctl system call and the "old shm interface."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 1.9
Exploit Score: 3.4
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
http://www.securityfocus.com/archive/1/520102/100/0/threaded
SECUNIA-42758
SECUNIA-42778
SECUNIA-42884
SECUNIA-42890
SECUNIA-42932
SECUNIA-42963
SECUNIA-43161
SECUNIA-43291
BID-45054
SECUNIA-46397
ADV-2011-0012
ADV-2011-0070
ADV-2011-0124
ADV-2011-0168
ADV-2011-0280
ADV-2011-0298
ADV-2011-0375
DSA-2126
MDVSA-2011:029
MDVSA-2011:051
RHSA-2010:0958
RHSA-2011:0007
RHSA-2011:0017
RHSA-2011:0162
SUSE-SA:2010:060
SUSE-SA:2011:001
SUSE-SA:2011:004
SUSE-SA:2011:007
SUSE-SA:2011:008
USN-1041-1
USN-1057-1
http://lkml.org/lkml/2010/10/6/454
http://www.openwall.com/lists/oss-security/2010/10/07/1
http://www.openwall.com/lists/oss-security/2010/10/25/3
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3af54c9bd9e6f14f896aac1bb0e8405ae0bc7a44
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.37-rc1
http://www.vmware.com/security/advisories/VMSA-2011-0012.html
https://bugzilla.redhat.com/show_bug.cgi?id=648656

CPE    7
cpe:/o:opensuse:opensuse:11.3
cpe:/o:debian:debian_linux:5.0
cpe:/o:suse:linux_enterprise_server:9
cpe:/o:canonical:ubuntu_linux:10.10
...
CWE    1
CWE-200
OVAL    28
oval:org.secpod.oval:def:400020
oval:org.secpod.oval:def:700243
oval:org.secpod.oval:def:500099
oval:org.secpod.oval:def:500112
...

© SecPod Technologies