ID |
CVE-2014-2568
|
Sažetak |
Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation. NOTE: the affected code was moved to the skb_zerocopy function in net/core/skbuff.c before the vulnerability was announced. |
Reference |
|
CVSS |
Base: | 2.9 |
Impact: | 2.9 |
Exploitability: | 5.5 |
|
Pristup |
Vektor | Složenost | Autentikacija |
ADJACENT_NETWORK |
MEDIUM |
NONE |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
PARTIAL |
NONE |
NONE |
|
CVSS vektor |
AV:A/AC:M/Au:N/C:P/I:N/A:N |
Zadnje važnije ažuriranje |
10-05-2019 - 13:53 |
Objavljeno |
24-03-2014 - 16:40 |