Lucene search

K
nvd[email protected]NVD:CVE-2010-4160
HistoryJan 07, 2011 - 12:00 p.m.

CVE-2010-4160

2011-01-0712:00:48
CWE-190
web.nvd.nist.gov

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

8.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%

Multiple integer overflows in the (1) pppol2tp_sendmsg function in net/l2tp/l2tp_ppp.c, and the (2) l2tp_ip_sendmsg function in net/l2tp/l2tp_ip.c, in the PPPoL2TP and IPoL2TP implementations in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (heap memory corruption and panic) or possibly gain privileges via a crafted sendto call.

Affected configurations

NVD
Node
linuxlinux_kernelRange<2.6.36.2
Node
opensuseopensuseMatch11.2
OR
suselinux_enterprise_desktopMatch10sp3
OR
suselinux_enterprise_desktopMatch11sp1
OR
suselinux_enterprise_serverMatch9
OR
suselinux_enterprise_serverMatch10sp3
OR
suselinux_enterprise_serverMatch11sp1
OR
suselinux_enterprise_software_development_kitMatch10sp3

References

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

8.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%