CVE-2013-3237 — Sensitive Information Exposure in Kernel
Severity
4.9MEDIUMNVD
EPSS
0.1%
top 77.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 22
Latest updateMay 17
Description
The vsock_stream_sendmsg function in net/vmw_vsock/af_vsock.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
CVSS vector
AV:L/AC:L/C:C/I:N/A:NExploitability: 3.9 | Impact: 6.9
Affected Packages2 packages
🔴Vulnerability Details
3📋Vendor Advisories
2💬Community
1Bugzilla
▶