CVE-2010-3437 - CERT CVE
ID CVE-2010-3437
Sažetak Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and system crash) via a crafted index value in a PKT_CTRL_CMD_STATUS ioctl call.
Reference
CVSS
Base: 6.6
Impact: 9.2
Exploitability:3.9
Pristup
VektorSloženostAutentikacija
LOCAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE NONE COMPLETE
CVSS vektor AV:L/AC:L/Au:N/C:C/I:N/A:C
Zadnje važnije ažuriranje 13-02-2023 - 04:24
Objavljeno 04-10-2010 - 21:00