1.9 Low
CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:L/AC:M/Au:N/C:P/I:N/A:N
2.3 Low
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
4.6 Medium
AI Score
Confidence
Low
0.0004 Low
EPSS
Percentile
12.6%
The (1) pptp_bind and (2) pptp_connect functions in drivers/net/ppp/pptp.c in the Linux kernel through 4.3.3 do not verify an address length, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism via a crafted application.
git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=09ccfd238e5a0e670d8178cf50180ea81ae09ae1
lists.fedoraproject.org/pipermail/package-announce/2016-February/176484.html
lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.html
lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.html
lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html
twitter.com/grsecurity/statuses/676744240802750464
www.debian.org/security/2016/dsa-3434
www.openwall.com/lists/oss-security/2015/12/15/11
www.securityfocus.com/bid/79428
www.securitytracker.com/id/1034549
www.ubuntu.com/usn/USN-2886-1
www.ubuntu.com/usn/USN-2888-1
www.ubuntu.com/usn/USN-2890-1
www.ubuntu.com/usn/USN-2890-2
www.ubuntu.com/usn/USN-2890-3
bugzilla.redhat.com/show_bug.cgi?id=1292045
github.com/torvalds/linux/commit/09ccfd238e5a0e670d8178cf50180ea81ae09ae1
lkml.org/lkml/2015/12/14/252
1.9 Low
CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:L/AC:M/Au:N/C:P/I:N/A:N
2.3 Low
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
4.6 Medium
AI Score
Confidence
Low
0.0004 Low
EPSS
Percentile
12.6%