Lucene search

K
nvd[email protected]NVD:CVE-2010-2942
HistorySep 21, 2010 - 6:00 p.m.

CVE-2010-2942

2010-09-2118:00:02
CWE-401
web.nvd.nist.gov
1

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

20.3%

The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the tcf_gact_dump function in net/sched/act_gact.c, (2) the tcf_mirred_dump function in net/sched/act_mirred.c, (3) the tcf_nat_dump function in net/sched/act_nat.c, (4) the tcf_simp_dump function in net/sched/act_simple.c, and (5) the tcf_skbedit_dump function in net/sched/act_skbedit.c.

Affected configurations

NVD
Node
linuxlinux_kernelRange≤2.6.35.13
OR
linuxlinux_kernelMatch2.6.36-
OR
linuxlinux_kernelMatch2.6.36rc1
Node
canonicalubuntu_linuxMatch6.06
OR
canonicalubuntu_linuxMatch8.04
OR
canonicalubuntu_linuxMatch9.04
OR
canonicalubuntu_linuxMatch9.10
OR
canonicalubuntu_linuxMatch10.04-
OR
canonicalubuntu_linuxMatch10.10
Node
opensuseopensuseMatch11.1
OR
opensuseopensuseMatch11.3
OR
susesuse_linux_enterprise_desktopMatch10sp3
OR
susesuse_linux_enterprise_desktopMatch11-
OR
susesuse_linux_enterprise_desktopMatch11sp1
OR
susesuse_linux_enterprise_serverMatch10sp3
OR
susesuse_linux_enterprise_serverMatch11-
OR
susesuse_linux_enterprise_serverMatch11sp1
Node
avayaaura_communication_managerMatch5.2
OR
avayaaura_presence_servicesMatch6.0
OR
avayaaura_presence_servicesMatch6.1
OR
avayaaura_presence_servicesMatch6.1.1
OR
avayaaura_session_managerMatch1.1
OR
avayaaura_session_managerMatch5.2
OR
avayaaura_session_managerMatch6.0
OR
avayaaura_system_managerMatch5.2
OR
avayaaura_system_managerMatch6.0
OR
avayaaura_system_managerMatch6.1
OR
avayaaura_system_managerMatch6.1.1
OR
avayaaura_system_platformMatch1.1
OR
avayaaura_system_platformMatch6.0-
OR
avayaaura_system_platformMatch6.0sp1
OR
avayaiqMatch5.0
OR
avayaiqMatch5.1
OR
avayavoice_portalMatch5.0
OR
avayavoice_portalMatch5.1-
OR
avayavoice_portalMatch5.1sp1
Node
vmwareesxMatch4.0
OR
vmwareesxMatch4.1

References

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

20.3%