Lucene search

K
nvd[email protected]NVD:CVE-2012-3520
HistoryOct 03, 2012 - 11:02 a.m.

CVE-2012-3520

2012-10-0311:02:57
CWE-287
web.nvd.nist.gov
8

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

Low

EPSS

0

Percentile

5.1%

The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Avahi or (2) NetworkManager.

Affected configurations

Nvd
Node
linuxlinux_kernelRange≀3.2.29
OR
linuxlinux_kernelMatch2.3.2
OR
linuxlinux_kernelMatch2.3.20
OR
linuxlinux_kernelMatch2.3.21
OR
linuxlinux_kernelMatch2.3.22
OR
linuxlinux_kernelMatch2.3.23
OR
linuxlinux_kernelMatch2.3.24
OR
linuxlinux_kernelMatch2.3.25
OR
linuxlinux_kernelMatch2.3.26
OR
linuxlinux_kernelMatch2.3.27
OR
linuxlinux_kernelMatch2.3.28
OR
linuxlinux_kernelMatch2.3.29
OR
linuxlinux_kernelMatch2.4.33.2
OR
linuxlinux_kernelMatch2.6.13.2
OR
linuxlinux_kernelMatch2.6.23.2
OR
linuxlinux_kernelMatch2.6.33.2
OR
linuxlinux_kernelMatch2.6.33.20
OR
linuxlinux_kernelMatch3.2
OR
linuxlinux_kernelMatch3.2rc2
OR
linuxlinux_kernelMatch3.2rc3
OR
linuxlinux_kernelMatch3.2rc4
OR
linuxlinux_kernelMatch3.2rc5
OR
linuxlinux_kernelMatch3.2rc6
OR
linuxlinux_kernelMatch3.2rc7
OR
linuxlinux_kernelMatch3.2.1
OR
linuxlinux_kernelMatch3.2.2
OR
linuxlinux_kernelMatch3.2.3
OR
linuxlinux_kernelMatch3.2.4
OR
linuxlinux_kernelMatch3.2.5
OR
linuxlinux_kernelMatch3.2.6
OR
linuxlinux_kernelMatch3.2.7
OR
linuxlinux_kernelMatch3.2.8
OR
linuxlinux_kernelMatch3.2.9
OR
linuxlinux_kernelMatch3.2.10
OR
linuxlinux_kernelMatch3.2.11
OR
linuxlinux_kernelMatch3.2.12
OR
linuxlinux_kernelMatch3.2.13
OR
linuxlinux_kernelMatch3.2.14
OR
linuxlinux_kernelMatch3.2.15
OR
linuxlinux_kernelMatch3.2.16
OR
linuxlinux_kernelMatch3.2.17
OR
linuxlinux_kernelMatch3.2.18
OR
linuxlinux_kernelMatch3.2.19
OR
linuxlinux_kernelMatch3.2.20
OR
linuxlinux_kernelMatch3.2.21
OR
linuxlinux_kernelMatch3.2.22
OR
linuxlinux_kernelMatch3.2.23
OR
linuxlinux_kernelMatch3.2.24
OR
linuxlinux_kernelMatch3.2.25
OR
linuxlinux_kernelMatch3.2.26
OR
linuxlinux_kernelMatch3.2.27
OR
linuxlinux_kernelMatch3.2.28
OR
linuxlinux_kernelMatch3.3.2

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

Low

EPSS

0

Percentile

5.1%