CVE-2014-1444
Published Jan 18, 2014
Last updated a year ago
Overview
- Description
- The fst_get_iface function in drivers/net/wan/farsync.c in the Linux kernel before 3.11.7 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability for an SIOCWANDEV ioctl call.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 1.7
- Impact score
- 2.9
- Exploitability score
- 3.1
- Vector string
- AV:L/AC:L/Au:S/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-399
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C3D55C7B-D6AF-4DB4-8CCC-3BFC8C15F45D", "versionEndIncluding": "3.11.6" }, { "criteria": "cpe:2.3:o:linux:linux_kernel:3.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "639E3A57-A9E7-40E6-8929-81CCC0060EFB" }, { "criteria": "cpe:2.3:o:linux:linux_kernel:3.11.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "07012ADD-F521-40A8-B067-E87C2238A3D2" }, { "criteria": "cpe:2.3:o:linux:linux_kernel:3.11.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3F5FF393-3F89-4274-B82B-F671358072ED" }, { "criteria": "cpe:2.3:o:linux:linux_kernel:3.11.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E348698F-54D1-4F5E-B701-CFAF50881E0A" }, { "criteria": "cpe:2.3:o:linux:linux_kernel:3.11.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "932205D9-3514-4289-9B55-C7A169276930" }, { "criteria": "cpe:2.3:o:linux:linux_kernel:3.11.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2ECB2D33-F517-480F-8A6F-99D9D6C49596" } ], "operator": "OR" } ] } ]