[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2016-4578Date: (C)2016-06-02   (M)2024-04-19


sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_timer_user_ccallback and (2) snd_timer_user_tinterrupt functions.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 5.5CVSS Score : 2.1
Exploit Score: 1.8Exploit Score: 3.9
Impact Score: 3.6Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector: LOCAL
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: LOWAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: NONE
Confidentiality: HIGHAvailability: NONE
Integrity: NONE 
Availability: NONE 
  
Reference:
EXPLOIT-DB-46529
BID-90535
DSA-3607
RHSA-2016:2574
RHSA-2016:2584
SUSE-SU-2016:1672
SUSE-SU-2016:1690
SUSE-SU-2016:1937
SUSE-SU-2016:1985
SUSE-SU-2016:2105
USN-3016-1
USN-3016-2
USN-3016-3
USN-3016-4
USN-3017-1
USN-3017-2
USN-3017-3
USN-3018-1
USN-3018-2
USN-3019-1
USN-3020-1
USN-3021-1
USN-3021-2
http://www.openwall.com/lists/oss-security/2016/05/11/5
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9a47e9cff994f37f7f0dbd9ae23740d0f64f9fe6
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e4ec8cc8039a7063e24204299b462bd1383184a5
https://bugzilla.redhat.com/show_bug.cgi?id=1335215
https://github.com/torvalds/linux/commit/9a47e9cff994f37f7f0dbd9ae23740d0f64f9fe6
https://github.com/torvalds/linux/commit/e4ec8cc8039a7063e24204299b462bd1383184a5
openSUSE-SU-2016:1641
openSUSE-SU-2016:2184

CPE    10
cpe:/o:canonical:ubuntu_linux:15.10
cpe:/o:linux:linux_kernel
cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~
cpe:/o:redhat:enterprise_linux_workstation:7.0
...
CWE    1
CWE-200
OVAL    35
oval:org.secpod.oval:def:703186
oval:org.secpod.oval:def:703185
oval:org.secpod.oval:def:703184
oval:org.secpod.oval:def:703182
...

© SecPod Technologies