CVE-2011-1079 - CERT CVE
ID CVE-2011-1079
Sažetak The bnep_sock_ioctl function in net/bluetooth/bnep/sock.c in the Linux kernel before 2.6.39 does not ensure that a certain device field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory, or cause a denial of service (BUG and system crash), via a BNEPCONNADD command.
Reference
CVSS
Base: 5.4
Impact: 7.8
Exploitability:3.4
Pristup
VektorSloženostAutentikacija
LOCAL MEDIUM NONE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL NONE COMPLETE
CVSS vektor AV:L/AC:M/Au:N/C:P/I:N/A:C
Zadnje važnije ažuriranje 13-02-2023 - 04:29
Objavljeno 21-06-2012 - 23:55