Lucene search

K
cvelistRedhatCVELIST:CVE-2011-1171
HistoryJun 22, 2011 - 10:00 p.m.

CVE-2011-1171

2011-06-2222:00:00
redhat
www.cve.org
1

7.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

net/ipv4/netfilter/ip_tables.c in the IPv4 implementation in the Linux kernel before 2.6.39 does not place the expected โ€˜\0โ€™ character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.