CVE-2010-3904
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
Affected (18)
Products: Linux: Linux Kernel · Opensuse: Opensuse · Suse: Linux Enterprise Desktop, Linux Enterprise Real Time Extension, Linux Enterprise Server · +3 more
Show all products
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.36 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.2 | |
| Version 11 sp1 | |
| Version 11 sp1 | |
| Version 11 sp1 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.04 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.0 |
References (39)
Source: security@ubuntu.com
Broken Link
Source: security@ubuntu.com
Mailing ListThird Party Advisory
Source: security@ubuntu.com
Mailing ListThird Party Advisory
Source: security@ubuntu.com
Mailing ListThird Party Advisory
Source: security@ubuntu.com
ExploitThird Party AdvisoryVDB Entry
Source: security@ubuntu.com
Broken LinkThird Party AdvisoryVDB Entry
Source: security@ubuntu.com
Third Party AdvisoryUS Government Resource
Source: security@ubuntu.com
Broken LinkThird Party Advisory
Source: security@ubuntu.com
Broken LinkThird Party Advisory
Source: security@ubuntu.com
Broken LinkThird Party AdvisoryVDB Entry
Source: security@ubuntu.com
Third Party Advisory
Source: security@ubuntu.com
Broken LinkThird Party Advisory
Source: security@ubuntu.com
Issue TrackingPatchThird Party Advisory
Source: security@ubuntu.com
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.