CVE Database
/

CVE-2009-3002

Back to search

CVE-2009-3002

Published: Aug 28, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows local users to read the contents of some kernel memory locations by calling getsockname on (1) an AF_APPLETALK socket, related to the atalk_getname function in net/appletalk/ddp.c; (2) an AF_IRDA socket, related to the irda_getname function in net/irda/af_irda.c; (3) an AF_ECONET socket, related to the econet_getname function in net/econet/af_econet.c; (4) an AF_NETROM socket, related to the nr_getname function in net/netrom/af_netrom.c; (5) an AF_ROSE socket, related to the rose_getname function in net/rose/af_rose.c; or (6) a raw CAN socket, related to the raw_getname function in net/can/raw.c.

VendorProductVersions

n/a

n/a

affected
n/a

References

oval:org.mitre.oval:def:11611
vdb-entry
signature
x_refsource_OVAL
RHSA-2009:1540
vendor-advisory
x_refsource_REDHAT
USN-852-1
vendor-advisory
x_refsource_UBUNTU
37351
third-party-advisory
x_refsource_SECUNIA
SUSE-SA:2009:056
vendor-advisory
x_refsource_SUSE
SUSE-SA:2010:012
vendor-advisory
x_refsource_SUSE
36150
vdb-entry
x_refsource_BID
RHSA-2009:1550
vendor-advisory
x_refsource_REDHAT
oval:org.mitre.oval:def:11741
vdb-entry
signature
x_refsource_OVAL
36438
third-party-advisory
x_refsource_SECUNIA
9521
exploit
x_refsource_EXPLOIT-DB
SUSE-SA:2009:054
vendor-advisory
x_refsource_SUSE
37105
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now