Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-1495

Опубликовано: 03 мая 2011
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 7.2

Описание

drivers/scsi/mpt2sas/mpt2sas_ctl.c in the Linux kernel 2.6.38 and earlier does not validate (1) length and (2) offset values before performing memory copy operations, which might allow local users to gain privileges, cause a denial of service (memory corruption), or obtain sensitive information from kernel memory via a crafted ioctl call, related to the _ctl_do_mpt_command and _ctl_diag_read_buffer functions.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

2.6.39-1.6
hardy

not-affected

lucid

released

2.6.32-33.64
maverick

released

2.6.35-30.52
natty

released

2.6.38-10.44
upstream

released

2.6.39~rc6

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

DNE

lucid

released

2.6.32-317.32
maverick

ignored

end of life
natty

DNE

upstream

released

2.6.39~rc6

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

DNE

lucid

released

2.6.31-609.26
maverick

DNE

natty

DNE

upstream

released

2.6.39~rc6

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

DNE

lucid

released

2.6.35-30.54~lucid1
maverick

DNE

natty

DNE

upstream

released

2.6.39~rc6

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

DNE

lucid

not-affected

2.6.38-10.44~lucid1
maverick

DNE

natty

DNE

upstream

released

2.6.39~rc6

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

DNE

lucid

released

2.6.32-217.34
maverick

released

2.6.32-417.34
natty

DNE

upstream

released

2.6.39~rc6

Показывать по

РелизСтатусПримечание
dapper

ignored

devel

DNE

hardy

DNE

lucid

DNE

maverick

DNE

natty

DNE

upstream

released

2.6.39~rc6

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

3.0.0-1204.9
hardy

DNE

lucid

DNE

maverick

released

2.6.35-903.23
natty

released

2.6.38-1209.15
upstream

released

2.6.39~rc6

Показывать по

EPSS

Процентиль: 34%
0.00132
Низкий

7.2 High

CVSS2

Связанные уязвимости

redhat
около 14 лет назад

drivers/scsi/mpt2sas/mpt2sas_ctl.c in the Linux kernel 2.6.38 and earlier does not validate (1) length and (2) offset values before performing memory copy operations, which might allow local users to gain privileges, cause a denial of service (memory corruption), or obtain sensitive information from kernel memory via a crafted ioctl call, related to the _ctl_do_mpt_command and _ctl_diag_read_buffer functions.

nvd
около 14 лет назад

drivers/scsi/mpt2sas/mpt2sas_ctl.c in the Linux kernel 2.6.38 and earlier does not validate (1) length and (2) offset values before performing memory copy operations, which might allow local users to gain privileges, cause a denial of service (memory corruption), or obtain sensitive information from kernel memory via a crafted ioctl call, related to the _ctl_do_mpt_command and _ctl_diag_read_buffer functions.

debian
около 14 лет назад

drivers/scsi/mpt2sas/mpt2sas_ctl.c in the Linux kernel 2.6.38 and earl ...

github
около 3 лет назад

drivers/scsi/mpt2sas/mpt2sas_ctl.c in the Linux kernel 2.6.38 and earlier does not validate (1) length and (2) offset values before performing memory copy operations, which might allow local users to gain privileges, cause a denial of service (memory corruption), or obtain sensitive information from kernel memory via a crafted ioctl call, related to the _ctl_do_mpt_command and _ctl_diag_read_buffer functions.

oracle-oval
около 14 лет назад

ELSA-2011-2016: Unbreakable Enterprise kernel security fix update (IMPORTANT)

EPSS

Процентиль: 34%
0.00132
Низкий

7.2 High

CVSS2