CVE-2014-4027
2.3
Vector
AV:A/AC:M/Au:S/C:P/I:N/A:N
Exploitability: 4.4 / Impact: 2.9
Source: NVD
Description
The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from ramdisk_mcp memory by leveraging access to a SCSI initiator.
Affected (35)
Show all products
Linux: Linux Kernel · Redhat: Enterprise Linux · Canonical: Ubuntu Linux · Suse: Linux Enterprise Desktop, Linux Enterprise High Availability Extension, Linux Enterprise Real Time Extension, Linux Enterprise Server · F5: Big Ip Access Policy Manager, Big Ip Advanced Firewall Manager, Big Ip Analytics, Big Ip Application Acceleration Manager, Big Ip Application Security Manager, Big Ip Domain Name System, Big Ip Edge Gateway, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Local Traffic Manager, Big Ip Policy Enforcement Manager, Big Ip Protocol Security Module, Big Ip Wan Optimization Manager, Big Ip Webaccelerator, Big Iq Application Delivery Controller, Big Iq Cloud, Big Iq Device, Big Iq Security, Enterprise Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.14 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.04 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11 sp3 | |
| Version 11 sp3 | |
| Version 11 sp3 | |
| Version 11 sp3 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.1.0 to 11.6.0 | |
| From 11.3.0 to 11.6.0 | |
| From 11.1.0 to 11.6.0 | |
| From 11.4.0 to 11.6.0 | |
| From 11.1.0 to 11.6.0 | |
| Version 12.0.0 | |
| From 11.1.0 to 11.3.0 | |
| From 11.1.0 to 11.6.0 | |
| From 11.1.0 to 11.6.0 | |
| From 11.1.0 to 11.6.0 | |
| From 11.3.0 to 11.6.0 | |
| From 11.1.0 to 11.4.1 | |
| From 11.1.0 to 11.3.0 | |
| From 11.1.0 to 11.3.0 | |
| Version 4.5.0 | |
| From 4.0.0 to 4.5.0 | |
| From 4.2.0 to 4.5.0 | |
| From 4.0.0 to 4.5.0 | |
| From 3.0.0 to 3.1.1 |
References (28)
Source: cve@mitre.org
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListPatchThird Party Advisory
Source: cve@mitre.org
Issue TrackingPatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.