Lucene search

K
cve[email protected]CVE-2016-4913
HistoryMay 23, 2016 - 10:59 a.m.

CVE-2016-4913

2016-05-2310:59:14
CWE-200
web.nvd.nist.gov
153
cve-2016-4913
linux kernel
security vulnerability
nm entries
isofs filesystem
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.4 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.3%

The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem.

Affected configurations

NVD
Node
canonicalubuntu_linuxMatch12.04lts
OR
canonicalubuntu_linuxMatch14.04lts
OR
canonicalubuntu_linuxMatch15.10
OR
canonicalubuntu_linuxMatch16.04lts
Node
linuxlinux_kernelRange<3.2.81
OR
linuxlinux_kernelRange3.33.10.102
OR
linuxlinux_kernelRange3.113.12.60
OR
linuxlinux_kernelRange3.133.14.70
OR
linuxlinux_kernelRange3.153.16.36
OR
linuxlinux_kernelRange3.173.18.34
OR
linuxlinux_kernelRange3.194.1.25
OR
linuxlinux_kernelRange4.24.4.11
OR
linuxlinux_kernelRange4.54.5.5
Node
oraclelinuxMatch6
Node
novellsuse_linux_enterprise_software_development_kitMatch11.0sp4
OR
novellsuse_linux_enterprise_debuginfoMatch11.0sp4
OR
novellsuse_linux_enterprise_serverMatch11.0extra
OR
novellsuse_linux_enterprise_serverMatch11.0sp4

References

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.4 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.3%