Lucene search

K
cve[email protected]CVE-2014-4652
HistoryJul 03, 2014 - 4:22 a.m.

CVE-2014-4652

2014-07-0304:22:15
CWE-362
web.nvd.nist.gov
60
cve-2014-4652
race condition
tlv handler
alsa
linux kernel
nvd
security vulnerability

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

5.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.2%

Race condition in the tlv handler functionality in the snd_ctl_elem_user_tlv function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allows local users to obtain sensitive information from kernel memory by leveraging /dev/snd/controlCX access.

Affected configurations

NVD
Node
linuxlinux_kernelRange<3.15.2
Node
suselinux_enterprise_serverMatch10sp4ltss
Node
canonicalubuntu_linuxMatch12.04esm
Node
redhatenterprise_linux_desktopMatch6.0
OR
redhatenterprise_linux_serverMatch6.0
OR
redhatenterprise_linux_workstationMatch6.0

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

5.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.2%