ShaikUsaf/linux-3.0.35

CVE-2012-6549 (Low) detected in linux-stable-rtv3.8.6

Opened this issue · 0 comments

CVE-2012-6549 - Low Severity Vulnerability

Vulnerable Library - linux-stable-rtv3.8.6

Julia Cartwright's fork of linux-stable-rt.git

Library home page: https://git.kernel.org/pub/scm/linux/kernel/git/julia/linux-stable-rt.git

Found in base branch: master

Vulnerable Source Files (3)

/fs/isofs/export.c
/fs/isofs/export.c
/fs/isofs/export.c

Vulnerability Details

The isofs_export_encode_fh function in fs/isofs/export.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted application.

Publish Date: 2013-03-15

URL: CVE-2012-6549

CVSS 3 Score Details (2.9)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Local
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://nvd.nist.gov/vuln/detail/CVE-2012-6549

Release Date: 2013-03-15

Fix Resolution: 3.6


Step up your Open Source Security Game with Mend here