INFORMATION
Name | : | CVE-2009-0676 | First Publication | : | 2009-02-22 |
Severity | : | Low | Last Modification | : | 2009-12-19 |
SCORING CVSS v2
Cvss Base Score | : | 2.1 | Attack Range | : | Local |
Cvss Impact Score | : | 2.9 | Attack Complexity | : | Low |
Cvss Expoit Score | : | 3.9 | Authentification | : | None Required |
Calculate full CVSS 2.0 Vectors scores | |||||
DETAIL
The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel memory via an SO_BSDCOMPAT getsockopt request.
Security Dashboard



(Low)
(Critical)
(High)
(Medium)








