Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-4655

Опубликовано: 18 июл. 2011
Источник: nvd
CVSS3: 5.5
CVSS2: 2.1
EPSS Низкий

Описание

net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability for an ethtool ioctl call.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Версия до 2.6.36 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:vmware:esx:4.0:*:*:*:*:*:*:*
cpe:2.3:o:vmware:esx:4.1:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*

EPSS

Процентиль: 17%
0.00053
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-665

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 14 лет назад

net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability for an ethtool ioctl call.

redhat
больше 14 лет назад

net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability for an ethtool ioctl call.

CVSS3: 5.5
debian
почти 14 лет назад

net/core/ethtool.c in the Linux kernel before 2.6.36 does not initiali ...

CVSS3: 5.5
github
около 3 лет назад

net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability for an ethtool ioctl call.

oracle-oval
больше 14 лет назад

ELSA-2011-0303: kernel security and bug fix update (MODERATE)

EPSS

Процентиль: 17%
0.00053
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-665