NVD

Id
14386  
Name
CVE-2010-2955  
Description
The cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the Linux kernel before 2.6.36-rc3-next-20100831 does not properly initialize certain structure members, which allows local users to leverage an off-by-one error in the ioctl_standard_iw_point function in net/wireless/wext-core.c, and obtain potentially sensitive information from kernel heap memory, via vectors involving an SIOCGIWESSID ioctl call that specifies a large buffer size.  
Reject
 
CVSS Version
2  
CVSS Score
3.3  
Severity
Low  
CVSS Base Score
3.3  
CVSS Impact Subscore
2.9  
CVSS Exploit Subscore
6.5  
CVSS Vector
(AV:A/AC:L/Au:N/C:P/I:N/A:N)  
Pub Date
2017-01-18  
Published
2010-09-08  
Modified Date
2012-03-19  
Seq
2010-2955  

Actions