CVE-2012-4467 - CERT CVE
ID CVE-2012-4467
Sažetak The (1) do_siocgstamp and (2) do_siocgstampns functions in net/socket.c in the Linux kernel before 3.5.4 use an incorrect argument order, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (system crash) via a crafted ioctl call.
Reference
CVSS
Base: 6.6
Impact: 9.2
Exploitability:3.9
Pristup
VektorSloženostAutentikacija
LOCAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE NONE COMPLETE
CVSS vektor AV:L/AC:L/Au:N/C:C/I:N/A:C
Zadnje važnije ažuriranje 13-02-2023 - 04:34
Objavljeno 10-10-2012 - 21:55