Lucene search

K
cveMitreCVE-2010-4072
HistoryNov 29, 2010 - 4:00 p.m.

CVE-2010-4072

2010-11-2916:00:02
CWE-200
mitre
web.nvd.nist.gov
74
linux kernel
cve-2010-4072
ipc
shm
sensitive information
security vulnerability

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

AI Score

5.8

Confidence

High

EPSS

0

Percentile

10.1%

The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the shmctl system call and the “old shm interface.”

Affected configurations

Nvd
Node
linuxlinux_kernelRange<2.6.37
OR
linuxlinux_kernelMatch2.6.37-
Node
opensuseopensuseMatch11.3
OR
suselinux_enterprise_desktopMatch10sp3
OR
suselinux_enterprise_desktopMatch11sp1
OR
suselinux_enterprise_real_time_extensionMatch11sp1
OR
suselinux_enterprise_serverMatch9
OR
suselinux_enterprise_serverMatch10sp3
OR
suselinux_enterprise_serverMatch11sp1
OR
suselinux_enterprise_software_development_kitMatch10sp3
Node
debiandebian_linuxMatch5.0
Node
canonicalubuntu_linuxMatch6.06
OR
canonicalubuntu_linuxMatch9.10
OR
canonicalubuntu_linuxMatch10.04-
OR
canonicalubuntu_linuxMatch10.10
VendorProductVersionCPE
linuxlinux_kernel*cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
linuxlinux_kernel2.6.37cpe:2.3:o:linux:linux_kernel:2.6.37:-:*:*:*:*:*:*
opensuseopensuse11.3cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:*
suselinux_enterprise_desktop10cpe:2.3:o:suse:linux_enterprise_desktop:10:sp3:*:*:*:*:*:*
suselinux_enterprise_desktop11cpe:2.3:o:suse:linux_enterprise_desktop:11:sp1:*:*:*:*:*:*
suselinux_enterprise_real_time_extension11cpe:2.3:o:suse:linux_enterprise_real_time_extension:11:sp1:*:*:*:*:*:*
suselinux_enterprise_server9cpe:2.3:o:suse:linux_enterprise_server:9:*:*:*:*:*:*:*
suselinux_enterprise_server10cpe:2.3:o:suse:linux_enterprise_server:10:sp3:*:*:*:*:*:*
suselinux_enterprise_server11cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:*:*:*:*
suselinux_enterprise_software_development_kit10cpe:2.3:o:suse:linux_enterprise_software_development_kit:10:sp3:*:*:*:*:*:*
Rows per page:
1-10 of 151

References

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

AI Score

5.8

Confidence

High

EPSS

0

Percentile

10.1%