|
|
| |
|
| |
kernel: information leak
| Package(s): | linux |
CVE #(s): | CVE-2013-3226
|
| Created: | May 24, 2013 |
Updated: | May 30, 2013 |
| Description: |
From the CVE entry:
The sco_sock_recvmsg function in net/bluetooth/sco.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call. |
| Alerts: |
|
( Log in to post comments)
|
|
|