CVE-2008-2729
kernel: [x86_64] The string instruction version didn't zero the output on exception.
Severity Score
4.9
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
arch/x86_64/lib/copy_user.S in the Linux kernel before 2.6.19 on some AMD64 systems does not erase destination memory locations after an exception during kernel memory copy, which allows local users to obtain sensitive information.
arch/x86_64/lib/copy_user.S en el kernel de Linux anterior a 2.6.19 en algunos sistemas AMD64 no borra las posiciones de memoria de destino después de una excepción, durante la copia de memoria del kernel, lo que permite a usuarios locales obtener información sensible.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2008-06-16 CVE Reserved
- 2008-06-30 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (18)
URL | Tag | Source |
---|---|---|
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=3022d734a54cbd2b65eea9a024564821101b4a9a%3Bhp=f0f4c3432e5e1087b3a8c0e6bd4113d3c37497ff | X_refsource_confirm | |
http://secunia.com/advisories/30849 | Broken Link | |
http://secunia.com/advisories/30850 | Broken Link | |
http://secunia.com/advisories/31107 | Broken Link | |
http://secunia.com/advisories/31551 | Broken Link | |
http://secunia.com/advisories/31628 | Broken Link | |
http://www.securityfocus.com/bid/29943 | Third Party Advisory | |
http://www.securitytracker.com/id?1020364 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/43558 | Third Party Advisory | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11571 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2008-0508.html | 2023-11-07 | |
http://www.debian.org/security/2008/dsa-1630 | 2023-11-07 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2008:174 | 2023-11-07 | |
http://www.redhat.com/support/errata/RHSA-2008-0519.html | 2023-11-07 | |
http://www.redhat.com/support/errata/RHSA-2008-0585.html | 2023-11-07 | |
http://www.ubuntu.com/usn/usn-625-1 | 2023-11-07 | |
https://bugzilla.redhat.com/show_bug.cgi?id=451271 | 2008-08-26 | |
https://access.redhat.com/security/cve/CVE-2008-2729 | 2008-08-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | < 2.6.19 Search vendor "Linux" for product "Linux Kernel" and version " < 2.6.19" | - |
Affected
|