Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-2898

Опубликовано: 07 июн. 2011
Источник: redhat
CVSS2: 1.9
EPSS Низкий

Описание

net/packet/af_packet.c in the Linux kernel before 2.6.39.3 does not properly restrict user-space access to certain packet data structures associated with VLAN Tag Control Information, which allows local users to obtain potentially sensitive information via a crafted application.

Отчет

This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 and 5 as they did not backport the upstream commit 393e52e3 that introduced this flaw. This has been addressed in Red Hat Enterprise Linux 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1350.html and https://rhn.redhat.com/errata/RHSA-2012-0010.html.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4kernelNot affected
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelFixedRHSA-2011:135005.10.2011
Red Hat Enterprise MRG 2kernel-rtFixedRHSA-2012:001010.01.2012

Показывать по

Дополнительная информация

Статус:

Low

EPSS

Процентиль: 24%
0.00078
Низкий

1.9 Low

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 13 лет назад

net/packet/af_packet.c in the Linux kernel before 2.6.39.3 does not properly restrict user-space access to certain packet data structures associated with VLAN Tag Control Information, which allows local users to obtain potentially sensitive information via a crafted application.

CVSS3: 5.5
nvd
около 13 лет назад

net/packet/af_packet.c in the Linux kernel before 2.6.39.3 does not properly restrict user-space access to certain packet data structures associated with VLAN Tag Control Information, which allows local users to obtain potentially sensitive information via a crafted application.

CVSS3: 5.5
debian
около 13 лет назад

net/packet/af_packet.c in the Linux kernel before 2.6.39.3 does not pr ...

CVSS3: 5.5
github
около 3 лет назад

net/packet/af_packet.c in the Linux kernel before 2.6.39.3 does not properly restrict user-space access to certain packet data structures associated with VLAN Tag Control Information, which allows local users to obtain potentially sensitive information via a crafted application.

oracle-oval
почти 14 лет назад

ELSA-2011-2029: Unbreakable Enterprise kernel security update (IMPORTANT)

EPSS

Процентиль: 24%
0.00078
Низкий

1.9 Low

CVSS2