Lucene search

K
cveRedhatCVE-2011-1160
HistoryJun 21, 2012 - 11:55 p.m.

CVE-2011-1160

2012-06-2123:55:02
CWE-200
redhat
web.nvd.nist.gov
94
cve-2011-1160
tpm_open function
linux kernel
information security
local users
kernel memory
vulnerability
nvd

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

5.1%

The tpm_open function in drivers/char/tpm/tpm.c in the Linux kernel before 2.6.39 does not initialize a certain buffer, which allows local users to obtain potentially sensitive information from kernel memory via unspecified vectors.

Affected configurations

Nvd
Node
linuxlinux_kernelRange≤2.6.38.8
OR
linuxlinux_kernelMatch2.6.38
OR
linuxlinux_kernelMatch2.6.38rc1
OR
linuxlinux_kernelMatch2.6.38rc2
OR
linuxlinux_kernelMatch2.6.38rc3
OR
linuxlinux_kernelMatch2.6.38rc4
OR
linuxlinux_kernelMatch2.6.38rc5
OR
linuxlinux_kernelMatch2.6.38rc6
OR
linuxlinux_kernelMatch2.6.38rc7
OR
linuxlinux_kernelMatch2.6.38rc8
OR
linuxlinux_kernelMatch2.6.38.1
OR
linuxlinux_kernelMatch2.6.38.2
OR
linuxlinux_kernelMatch2.6.38.3
OR
linuxlinux_kernelMatch2.6.38.4
OR
linuxlinux_kernelMatch2.6.38.5
OR
linuxlinux_kernelMatch2.6.38.6
OR
linuxlinux_kernelMatch2.6.38.7
VendorProductVersionCPE
linuxlinux_kernel2.6.38.5cpe:/o:linux:linux_kernel:2.6.38.5:::
linuxlinux_kernel2.6.38cpe:/o:linux:linux_kernel:2.6.38:rc5::
linuxlinux_kernel2.6.38cpe:/o:linux:linux_kernel:2.6.38:rc8::
linuxlinux_kernel2.6.38cpe:/o:linux:linux_kernel:2.6.38:rc3::
linuxlinux_kernel2.6.38.2cpe:/o:linux:linux_kernel:2.6.38.2:::
linuxlinux_kernel2.6.38.6cpe:/o:linux:linux_kernel:2.6.38.6:::
linuxlinux_kernel2.6.38cpe:/o:linux:linux_kernel:2.6.38:::
linuxlinux_kernel2.6.38.7cpe:/o:linux:linux_kernel:2.6.38.7:::
linuxlinux_kernel2.6.38cpe:/o:linux:linux_kernel:2.6.38:rc7::
linuxlinux_kernel2.6.38.4cpe:/o:linux:linux_kernel:2.6.38.4:::
Rows per page:
1-10 of 171

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

5.1%