Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-0010
HistoryFeb 12, 2008 - 12:00 a.m.

CVE-2008-0010

2008-02-1200:00:00
ubuntu.com
ubuntu.com
12

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

10.1%

The copy_from_user_mmap_sem function in fs/splice.c in the Linux kernel
2.6.22 through 2.6.24 does not validate a certain userspace pointer before
dereference, which allow local users to read from arbitrary kernel memory
locations.

Bugs

Notes

Author Note
jdstrand dapper-gutsy not affected. Only 2.6.23 - 2.6.24. See: http://isec.pl/vulnerabilities/isec-0026-vmsplice_to_kernel.txt local root exploit on hardy (exploit code exists) amitk will upload 2.6.24.2 for hardy soon

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

10.1%