Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-1170

Опубликовано: 22 июн. 2011
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 2.1

Описание

net/ipv4/netfilter/arp_tables.c in the IPv4 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.

РелизСтатусПримечание
devel

not-affected

2.6.39-0.1
hardy

released

2.6.24-29.92
lucid

released

2.6.32-32.62
maverick

released

2.6.35-30.52
natty

released

2.6.38-9.43
upstream

released

2.6.39~rc1

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

DNE

lucid

released

2.6.32-316.30
maverick

ignored

end of life
natty

DNE

upstream

released

2.6.39~rc1

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

DNE

lucid

released

2.6.31-610.27
maverick

DNE

natty

DNE

upstream

released

2.6.39~rc1

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

DNE

lucid

released

2.6.35-30.54~lucid1
maverick

DNE

natty

DNE

upstream

released

2.6.39~rc1

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

DNE

lucid

not-affected

2.6.38-9.43~lucid1
maverick

DNE

natty

DNE

upstream

released

2.6.39~rc1

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

DNE

lucid

released

2.6.32-217.34
maverick

released

2.6.32-417.34
natty

DNE

upstream

released

2.6.39~rc1

Показывать по

РелизСтатусПримечание
devel

not-affected

2.6.38-1309.13
hardy

DNE

lucid

DNE

maverick

released

2.6.35-903.23
natty

released

2.6.38-1209.13
upstream

released

2.6.39~rc1

Показывать по

EPSS

Процентиль: 12%
0.00041
Низкий

2.1 Low

CVSS2

Связанные уязвимости

redhat
больше 14 лет назад

net/ipv4/netfilter/arp_tables.c in the IPv4 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.

nvd
почти 14 лет назад

net/ipv4/netfilter/arp_tables.c in the IPv4 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.

debian
почти 14 лет назад

net/ipv4/netfilter/arp_tables.c in the IPv4 implementation in the Linu ...

github
около 3 лет назад

net/ipv4/netfilter/arp_tables.c in the IPv4 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.

oracle-oval
около 14 лет назад

ELSA-2011-2016: Unbreakable Enterprise kernel security fix update (IMPORTANT)

EPSS

Процентиль: 12%
0.00041
Низкий

2.1 Low

CVSS2

Уязвимость CVE-2011-1170