NVD

Id
38326  
Name
CVE-2013-2239  
Description
vzkernel before 042stab080.2 in the OpenVZ modification for the Linux kernel 2.6.32 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via (1) a crafted ploop driver ioctl call, related to the ploop_getdevice_ioc function in drivers/block/ploop/dev.c, or (2) a crafted quotactl system call, related to the compat_quotactl function in fs/quota/quota.c.  
Reject
 
CVSS Version
2  
CVSS Score
4.7  
Severity
Medium  
CVSS Base Score
4.7  
CVSS Impact Subscore
6.9  
CVSS Exploit Subscore
3.4  
CVSS Vector
(AV:L/AC:M/Au:N/C:C/I:N/A:N)  
Pub Date
2017-01-18  
Published
2013-11-12  
Modified Date
2014-02-06  
Seq
2013-2239  

Actions