CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:L/AC:L/Au:N/C:P/I:N/A:N
EPSS
Percentile
5.1%
Software suspend 2 2-2.2.1, when used with the Linux kernel 2.6.16, stores
pre-boot authentication passwords in the BIOS Keyboard buffer and does not
clear this buffer after use, which allows local users to obtain sensitive
information by reading the physical memory locations associated with this
buffer.
Author | Note |
---|---|
jdstrand | requires root access to the machine which gives access to do anything anyway (unless restricting root access via SELinux, which Ubuntu does not) |