PT-2017-13285 · Linux+2 · Linux Kernel+2

Sohu0106

·

Publicado

2017-09-05

·

Atualizado

2018-07-09

·

CVE-2017-14156

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.12.10
Description The issue allows local users to obtain sensitive information from kernel stack memory. This is due to the atyfb ioctl function in drivers/video/fbdev/aty/atyfb base.c not initializing a certain data structure, enabling users to read locations associated with padding bytes.
Recommendations For Linux kernel versions prior to 4.12.10, update to version 4.12.10 or later to resolve the issue.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2171
ALT-PU-2018-1991
CVE-2017-14156
DLA-1099-1
DSA-3981-1
MGASA-2017-0381
MGASA-2017-0383
MGASA-2017-0384
MGASA-2017-0386
MGASA-2017-0387
MGASA-2017-0388
USN-3469-1
USN-3469-2
USN-3487-1
USN-3583-1
USN-3583-2

Produtos afetados

Alt Linux
Linux Kernel
Ubuntu