cbcvebase.
CVE-2014-4943
published 2014-07-19

CVE-2014-4943: The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure differences…

medium6.9CVSS 3.1
AVLACMAuNCCICAC
EXPLOIT
The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure differences between an l2tp socket and an inet socket.

Affected

17 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 3.14.13-1 (bookworm)linux 3.14.13-1 (bookworm)
linuxlinux_kernel>= 0 < 3.14.13-13.14.13-1
linuxlinux_kernel>= 0 < 3.14.13-13.14.13-1
linuxlinux_kernel>= 0 < 3.14.13-13.14.13-1
linuxlinux_kernel>= 0 < 3.14.13-13.14.13-1
linuxlinux_kernel>= 0 < 3.13.0-32.573.13.0-32.57
linuxlinux_kernel>= 2.6.23 < 3.2.623.2.62
linuxlinux_kernel>= 3.11 < 3.12.273.12.27
linuxlinux_kernel>= 3.13 < 3.14.163.14.16
linuxlinux_kernel>= 3.15 < 3.15.93.15.9
linuxlinux_kernel>= 3.3 < 3.4.1023.4.102
linuxlinux_kernel>= 3.5 < 3.10.523.10.52
opensuseopensuse
redhatenterprise_linux_server_aus
suselinux_enterprise_desktop
suselinux_enterprise_server

CVSS provenance

nvd6.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM