CVE-2011-1173
Last modified
CVE-2011-1173 is a vulnerability of currently unknown severity. The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.39 on the x86_64 platform allows remote attackers to obtain potentially sensitive information from kernel stack memory by reading uninitialized data in the ah field of an Acorn Universal Networking (AUN) packet.. EPSS estimates a 2.61% chance of exploitation in the next 30 days.
Description
The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.39 on the x86_64 platform allows remote attackers to obtain potentially sensitive information from kernel stack memory by reading uninitialized data in the ah field of an Acorn Universal Networking (AUN) packet.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 2.6.39 |
References
- http://marc.info/?l=linux-netdev&m=130036203528021&w=2Patch, Third Party Advisory
- http://securityreason.com/securityalert/8279Third Party Advisory
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39Release Notes, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2011/03/18/15Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2011/03/21/1Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2011/03/21/4Mailing List, Patch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=591815#c14Issue Tracking, Third Party Advisory
- http://marc.info/?l=linux-netdev&m=130036203528021&w=2Patch, Third Party Advisory
- http://securityreason.com/securityalert/8279Third Party Advisory
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.39Release Notes, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2011/03/18/15Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2011/03/21/1Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2011/03/21/4Mailing List, Patch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=591815#c14Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-1173?
How severe is CVE-2011-1173?
How do I fix CVE-2011-1173?
Are you affected by CVE-2011-1173?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
