Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-7273

Опубликовано: 21 фев. 2018
Источник: nvd
CVSS3: 5.5
CVSS2: 4.9
EPSS Низкий

Описание

In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables using printk calls within the function show_floppy in drivers/block/floppy.c. An attacker can read this information from dmesg and use the addresses to find the locations of kernel code and data and bypass kernel security protections such as KASLR.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Версия до 4.15.4 (включая)

EPSS

Процентиль: 82%
0.01682
Низкий

5.5 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 8 лет назад

In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables using printk calls within the function show_floppy in drivers/block/floppy.c. An attacker can read this information from dmesg and use the addresses to find the locations of kernel code and data and bypass kernel security protections such as KASLR.

CVSS3: 2.5
redhat
почти 8 лет назад

In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables using printk calls within the function show_floppy in drivers/block/floppy.c. An attacker can read this information from dmesg and use the addresses to find the locations of kernel code and data and bypass kernel security protections such as KASLR.

CVSS3: 5.5
debian
почти 8 лет назад

In the Linux kernel through 4.15.4, the floppy driver reveals the addr ...

CVSS3: 5.5
github
больше 3 лет назад

In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables using printk calls within the function show_floppy in drivers/block/floppy.c. An attacker can read this information from dmesg and use the addresses to find the locations of kernel code and data and bypass kernel security protections such as KASLR.

CVSS3: 5.5
fstec
около 8 лет назад

Уязвимость функции show_floppy (drivers/block/floppy.c) ядра операционной системы Linux, позволяющая нарушителю обойти защиту ядра и получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 82%
0.01682
Низкий

5.5 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-200