Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-14331

Опубликовано: 15 сент. 2020
Источник: debian
EPSS Низкий

Описание

A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker attempts to resize the console, calling an ioctl VT_RESIZE, which causes an out-of-bounds write to occur. This flaw allows a local user with access to the VGA console to crash the system, potentially escalating their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed5.7.17-1package
linuxfixed4.19.146-1busterpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2020/07/28/2

  • Only exploitable when CONFIG_VGACON_SOFT_SCROLLBACK is set

EPSS

Процентиль: 5%
0.00025
Низкий

Связанные уязвимости

CVSS3: 6.6
ubuntu
почти 5 лет назад

A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker attempts to resize the console, calling an ioctl VT_RESIZE, which causes an out-of-bounds write to occur. This flaw allows a local user with access to the VGA console to crash the system, potentially escalating their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.6
redhat
почти 5 лет назад

A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker attempts to resize the console, calling an ioctl VT_RESIZE, which causes an out-of-bounds write to occur. This flaw allows a local user with access to the VGA console to crash the system, potentially escalating their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.6
nvd
почти 5 лет назад

A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker attempts to resize the console, calling an ioctl VT_RESIZE, which causes an out-of-bounds write to occur. This flaw allows a local user with access to the VGA console to crash the system, potentially escalating their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.6
msrc
больше 4 лет назад

Описание отсутствует

suse-cvrf
почти 5 лет назад

Security update for the Linux Kernel (Live Patch 1 for SLE 15 SP2)

EPSS

Процентиль: 5%
0.00025
Низкий