PT-2017-13775 · Linux+2 · Linux Kernel+2
Publicado
2017-10-01
·
Atualizado
2018-07-09
·
CVE-2017-14954
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions through 4.13.4
Description
The issue allows local users to obtain sensitive information and bypass the KASLR protection mechanism via a crafted system call, due to unintended access to rusage data structures in the waitid implementation.
Recommendations
For Linux kernel versions through 4.13.4, update to a version that contains a fix for this issue to prevent local users from obtaining sensitive information and bypassing the KASLR protection mechanism.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Linux Kernel
Ubuntu