Lucene search

K
cve[email protected]CVE-2010-2963
HistoryNov 26, 2010 - 7:00 p.m.

CVE-2010-2963

2010-11-2619:00:06
CWE-20
web.nvd.nist.gov
58
2
cve-2010-2963
v4l2
video4linux
kernel
privilege escalation
security vulnerability
nvd

6.2 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:C/I:C/A:C

6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

0.4%

drivers/media/video/v4l2-compat-ioctl32.c in the Video4Linux (V4L) implementation in the Linux kernel before 2.6.36 on 64-bit platforms does not validate the destination of a memory copy operation, which allows local users to write to arbitrary kernel memory locations, and consequently gain privileges, via a VIDIOCSTUNER ioctl call on a /dev/video device, followed by a VIDIOCSMICROCODE ioctl call on this device.

Affected configurations

NVD
Node
linuxlinux_kernelRange<2.6.36x64
Node
fedoraprojectfedoraMatch13
Node
opensuseopensuseMatch11.2
OR
opensuseopensuseMatch11.3
OR
suselinux_enterprise_desktopMatch11sp1
OR
suselinux_enterprise_serverMatch11sp1
Node
debiandebian_linuxMatch5.0
Node
canonicalubuntu_linuxMatch6.06
OR
canonicalubuntu_linuxMatch8.04-
OR
canonicalubuntu_linuxMatch9.04
OR
canonicalubuntu_linuxMatch9.10
OR
canonicalubuntu_linuxMatch10.04-
OR
canonicalubuntu_linuxMatch10.10

Social References

More

6.2 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:C/I:C/A:C

6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

0.4%