2.1 Low
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:L/AC:L/Au:N/C:P/I:N/A:N
0.0004 Low
EPSS
Percentile
10.5%
The media_device_enum_entities function in drivers/media/media-device.c in
the Linux kernel before 3.14.6 does not initialize a certain data
structure, which allows local users to obtain sensitive information from
kernel memory by leveraging /dev/media0 read access for a
MEDIA_IOC_ENUM_ENTITIES ioctl call.
Author | Note |
---|---|
jdstrand | android kernels (goldfish, grouper, maguro, mako and manta) are not supported on the Ubuntu Touch 13.10 preview kernels android kernels (flo, goldfish, grouper, maguro, mako and manta) are not supported on the Ubuntu Touch 14.04 preview kernels |
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 12.04 | noarch | linux | <Β 3.2.0-65.98 | UNKNOWN |
ubuntu | 13.10 | noarch | linux | <Β 3.11.0-24.41 | UNKNOWN |
ubuntu | 14.04 | noarch | linux | <Β 3.13.0-32.57 | UNKNOWN |
ubuntu | 12.04 | noarch | linux-armadaxp | <Β 3.2.0-1635.50 | UNKNOWN |
ubuntu | 12.04 | noarch | linux-lts-quantal | <Β 3.5.0-54.81~precise1 | UNKNOWN |
ubuntu | 12.04 | noarch | linux-lts-raring | <Β 3.8.0-44.66~precise1 | UNKNOWN |
ubuntu | 12.04 | noarch | linux-lts-saucy | <Β 3.11.0-24.41~precise1 | UNKNOWN |
ubuntu | 12.04 | noarch | linux-lts-trusty | <Β 3.13.0-32.57~precise1 | UNKNOWN |
ubuntu | 12.04 | noarch | linux-ti-omap4 | <Β 3.2.0-1450.69 | UNKNOWN |
git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e6a623460e5fc960ac3ee9f946d3106233fd28d8
launchpad.net/bugs/cve/CVE-2014-1739
nvd.nist.gov/vuln/detail/CVE-2014-1739
security-tracker.debian.org/tracker/CVE-2014-1739
ubuntu.com/security/notices/USN-2259-1
ubuntu.com/security/notices/USN-2261-1
ubuntu.com/security/notices/USN-2263-1
ubuntu.com/security/notices/USN-2264-1
ubuntu.com/security/notices/USN-2285-1
ubuntu.com/security/notices/USN-2286-1
ubuntu.com/security/notices/USN-2288-1
ubuntu.com/security/notices/USN-2290-1
www.cve.org/CVERecord?id=CVE-2014-1739