4.9
CVSSv2

CVE-2013-3237

Published: 22/04/2013 Updated: 07/11/2023
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
VMScore: 437
Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

The vsock_stream_sendmsg function in net/vmw_vsock/af_vsock.c in the Linux kernel prior to 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

linux linux kernel 3.9

Vendor Advisories

Debian Bug report logs - #706557 open-vm-tools: CVE-2013-3237 Package: src:open-vm-tools; Maintainer for src:open-vm-tools is Bernd Zeimetz <bzed@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 1 May 2013 14:57:01 UTC Severity: important Tags: patch, security Found in version open-vm-t ...
The vsock_stream_sendmsg function in net/vmw_vsock/af_vsockc in the Linux kernel before 39-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call ...