Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-15102

Опубликовано: 15 нояб. 2017
Источник: nvd
CVSS3: 6.3
CVSS2: 6.9
EPSS Низкий

Описание

The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-what-where condition that occurs after a race condition and a NULL pointer dereference.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Версия до 4.8.1 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*

EPSS

Процентиль: 30%
0.0011
Низкий

6.3 Medium

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 6.3
ubuntu
больше 7 лет назад

The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-what-where condition that occurs after a race condition and a NULL pointer dereference.

CVSS3: 6.3
redhat
почти 9 лет назад

The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-what-where condition that occurs after a race condition and a NULL pointer dereference.

CVSS3: 6.3
debian
больше 7 лет назад

The tower_probe function in drivers/usb/misc/legousbtower.c in the Lin ...

CVSS3: 6.3
github
около 3 лет назад

The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-what-where condition that occurs after a race condition and a NULL pointer dereference.

oracle-oval
больше 5 лет назад

ELSA-2019-4854: Unbreakable Enterprise kernel security update (IMPORTANT)

EPSS

Процентиль: 30%
0.0011
Низкий

6.3 Medium

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-476