CVE-2010-1083 - CERT CVE
ID CVE-2010-1083
Sažetak The processcompl_compat function in drivers/usb/core/devio.c in Linux kernel 2.6.x through 2.6.32, and possibly other versions, does not clear the transfer buffer before returning to userspace when a USB command fails, which might make it easier for physically proximate attackers to obtain sensitive information (kernel memory).
Reference
CVSS
Base: 4.7
Impact: 6.9
Exploitability:3.4
Pristup
VektorSloženostAutentikacija
LOCAL MEDIUM NONE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE NONE NONE
CVSS vektor AV:L/AC:M/Au:N/C:C/I:N/A:N
Zadnje važnije ažuriranje 10-10-2018 - 19:55
Objavljeno 06-04-2010 - 22:30