Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c9rp-95rg-526v

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability for an ethtool ioctl call.

net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability for an ethtool ioctl call.

EPSS

Процентиль: 17%
0.00053
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-665

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 14 лет назад

net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability for an ethtool ioctl call.

redhat
больше 14 лет назад

net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability for an ethtool ioctl call.

CVSS3: 5.5
nvd
почти 14 лет назад

net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability for an ethtool ioctl call.

CVSS3: 5.5
debian
почти 14 лет назад

net/core/ethtool.c in the Linux kernel before 2.6.36 does not initiali ...

oracle-oval
больше 14 лет назад

ELSA-2011-0303: kernel security and bug fix update (MODERATE)

EPSS

Процентиль: 17%
0.00053
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-665