Lucene search

K
nvd[email protected]NVD:CVE-2005-4881
HistoryOct 19, 2009 - 8:00 p.m.

CVE-2005-4881

2009-10-1920:00:00
CWE-200
web.nvd.nist.gov
1

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:C/I:N/A:N

7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.3%

The netlink subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.13-rc1 does not initialize certain padding fields in structures, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors, related to the (1) tc_fill_qdisc, (2) tcf_fill_node, (3) neightbl_fill_info, (4) neightbl_fill_param_info, (5) neigh_fill_info, (6) rtnetlink_fill_ifinfo, (7) rtnetlink_fill_iwinfo, (8) vif_delete, (9) ipmr_destroy_unres, (10) ipmr_cache_alloc_unres, (11) ipmr_cache_resolve, (12) inet6_fill_ifinfo, (13) tca_get_fill, (14) tca_action_flush, (15) tcf_add_notify, (16) tc_dump_action, (17) cbq_dump_police, (18) __nlmsg_put, (19) __rta_fill, (20) __rta_reserve, (21) inet6_fill_prefix, (22) rsvp_dump, and (23) cbq_dump_ovl functions.

Affected configurations

NVD
Node
linuxlinux_kernelMatch2.4.1
OR
linuxlinux_kernelMatch2.4.2
OR
linuxlinux_kernelMatch2.4.3
OR
linuxlinux_kernelMatch2.4.4
OR
linuxlinux_kernelMatch2.4.5
OR
linuxlinux_kernelMatch2.4.6
OR
linuxlinux_kernelMatch2.4.7
OR
linuxlinux_kernelMatch2.4.8
OR
linuxlinux_kernelMatch2.4.9
OR
linuxlinux_kernelMatch2.4.10
OR
linuxlinux_kernelMatch2.4.11
OR
linuxlinux_kernelMatch2.4.12
OR
linuxlinux_kernelMatch2.4.13
OR
linuxlinux_kernelMatch2.4.14
OR
linuxlinux_kernelMatch2.4.15
OR
linuxlinux_kernelMatch2.4.16
OR
linuxlinux_kernelMatch2.4.17
OR
linuxlinux_kernelMatch2.4.18
OR
linuxlinux_kernelMatch2.4.19
OR
linuxlinux_kernelMatch2.4.20
OR
linuxlinux_kernelMatch2.4.21
OR
linuxlinux_kernelMatch2.4.22
OR
linuxlinux_kernelMatch2.4.23
OR
linuxlinux_kernelMatch2.4.24
OR
linuxlinux_kernelMatch2.4.25
OR
linuxlinux_kernelMatch2.4.26
OR
linuxlinux_kernelMatch2.4.27
OR
linuxlinux_kernelMatch2.4.27-pre1
OR
linuxlinux_kernelMatch2.4.27-pre2
OR
linuxlinux_kernelMatch2.4.27-pre3
OR
linuxlinux_kernelMatch2.4.27-pre4
OR
linuxlinux_kernelMatch2.4.27-pre5
OR
linuxlinux_kernelMatch2.4.28
OR
linuxlinux_kernelMatch2.4.29
OR
linuxlinux_kernelMatch2.4.30
OR
linuxlinux_kernelMatch2.4.30rc2
OR
linuxlinux_kernelMatch2.4.30rc3
OR
linuxlinux_kernelMatch2.4.31
OR
linuxlinux_kernelMatch2.4.32
OR
linuxlinux_kernelMatch2.4.33
OR
linuxlinux_kernelMatch2.4.33.1
OR
linuxlinux_kernelMatch2.4.33.2
OR
linuxlinux_kernelMatch2.4.33.3
OR
linuxlinux_kernelMatch2.4.33.4
OR
linuxlinux_kernelMatch2.4.33.5
OR
linuxlinux_kernelMatch2.4.33.7
OR
linuxlinux_kernelMatch2.4.34
OR
linuxlinux_kernelMatch2.4.34.1
OR
linuxlinux_kernelMatch2.4.34.2
OR
linuxlinux_kernelMatch2.4.34.3
OR
linuxlinux_kernelMatch2.4.34.4
OR
linuxlinux_kernelMatch2.4.34.5
OR
linuxlinux_kernelMatch2.4.34.6
OR
linuxlinux_kernelMatch2.4.35.1
OR
linuxlinux_kernelMatch2.4.35.2
OR
linuxlinux_kernelMatch2.4.35.3
OR
linuxlinux_kernelMatch2.4.35.4
OR
linuxlinux_kernelMatch2.4.35.5
OR
linuxlinux_kernelMatch2.4.36
OR
linuxlinux_kernelMatch2.4.36.1
OR
linuxlinux_kernelMatch2.4.36.2
OR
linuxlinux_kernelMatch2.4.36.3
OR
linuxlinux_kernelMatch2.4.36.4
OR
linuxlinux_kernelMatch2.4.36.5
OR
linuxlinux_kernelMatch2.4.36.6
OR
linuxlinux_kernelMatch2.4.36.7
OR
linuxlinux_kernelMatch2.4.36.8
OR
linuxlinux_kernelMatch2.4.36.9
OR
linuxlinux_kernelMatch2.4.37
OR
linuxlinux_kernelMatch2.4.37.1
OR
linuxlinux_kernelMatch2.4.37.2
OR
linuxlinux_kernelMatch2.4.37.3
OR
linuxlinux_kernelMatch2.4.37.4
OR
linuxlinux_kernelMatch2.4.37.5
Node
linuxlinux_kernelMatch2.6.0
OR
linuxlinux_kernelMatch2.6.1
OR
linuxlinux_kernelMatch2.6.10
OR
linuxlinux_kernelMatch2.6.11
OR
linuxlinux_kernelMatch2.6.11.1
OR
linuxlinux_kernelMatch2.6.11.2
OR
linuxlinux_kernelMatch2.6.11.3
OR
linuxlinux_kernelMatch2.6.11.4
OR
linuxlinux_kernelMatch2.6.11.5
OR
linuxlinux_kernelMatch2.6.11.6
OR
linuxlinux_kernelMatch2.6.11.7
OR
linuxlinux_kernelMatch2.6.11.8
OR
linuxlinux_kernelMatch2.6.11.9
OR
linuxlinux_kernelMatch2.6.11.10
OR
linuxlinux_kernelMatch2.6.11.11
OR
linuxlinux_kernelMatch2.6.11.12
OR
linuxlinux_kernelMatch2.6.12
OR
linuxlinux_kernelMatch2.6.12.1
OR
linuxlinux_kernelMatch2.6.12.2
OR
linuxlinux_kernelMatch2.6.12.3
OR
linuxlinux_kernelMatch2.6.12.4
OR
linuxlinux_kernelMatch2.6.12.5
OR
linuxlinux_kernelMatch2.6.12.6

References

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:C/I:N/A:N

7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.3%