Lucene search

K
cve[email protected]CVE-2010-3849
HistoryDec 30, 2010 - 7:00 p.m.

CVE-2010-3849

2010-12-3019:00:03
CWE-476
web.nvd.nist.gov
56
2
cve
2010
3849
linux kernel
econet_sendmsg
net
denial of service
null pointer
oops
sendmsg
vulnerability

4.7 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:N/A:C

5.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.2%

The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a sendmsg call that specifies a NULL value for the remote address field.

Affected configurations

NVD
Node
linuxlinux_kernelRange<2.6.36.2
Node
suselinux_enterprise_desktopMatch10sp3
OR
suselinux_enterprise_real_time_extensionMatch11sp1
OR
suselinux_enterprise_serverMatch9
OR
suselinux_enterprise_serverMatch10sp3
OR
suselinux_enterprise_software_development_kitMatch10sp3
Node
debiandebian_linuxMatch5.0
Node
canonicalubuntu_linuxMatch6.06
OR
canonicalubuntu_linuxMatch8.04-
OR
canonicalubuntu_linuxMatch9.10
OR
canonicalubuntu_linuxMatch10.04-
OR
canonicalubuntu_linuxMatch10.10

References

Social References

More

4.7 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:N/A:C

5.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.2%