Vulnerability Name: | CVE-2010-3014 (CCN-61320) | ||||||||
Assigned: | 2010-08-16 | ||||||||
Published: | 2010-08-16 | ||||||||
Updated: | 2018-10-10 | ||||||||
Summary: | The Coda filesystem kernel module, as used in NetBSD and FreeBSD, when Coda is loaded and Venus is running with /coda mounted, allows local users to read sensitive heap memory via a large out_size value in a ViceIoctl struct to a Coda ioctl, which triggers a buffer over-read. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 1.2 Low (CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:N/A:N) 0.9 Low (Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-200 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Aug 16 2010 - 14:26:17 CDT CVE-2010-3014: Coda Filesystem Kernel Memory Disclosure Source: MITRE Type: CNA CVE-2010-3014 Source: CONFIRM Type: Patch http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/coda/coda.h.diff?r1=1.15&r2=1.16&only_with_tag=MAIN Source: CCN Type: NetBSD Security Advisory 2010-006 ocal Kernel Memory Information Disclosure Source: CCN Type: SA41166 NetBSD CODA Filesystem Kernel Memory Information Disclosure Vulnerability Source: CONFIRM Type: Patch http://svn.freebsd.org/viewvc/base?view=revision&revision=210997 Source: CCN Type: Coda Web page Coda Source: CCN Type: OSVDB ID: 67330 Coda Filesystem Kernel Module IOCTL ViceIoctl Struct Local Memory Disclosure Source: BUGTRAQ Type: UNKNOWN 20100816 CVE-2010-3014: Coda Filesystem Kernel Memory Disclosure Source: CCN Type: BID-43328 Fotobook Editor 'Fwpuclnt.dll' DLL Loading Arbitrary Code Execution Vulnerability Source: MISC Type: UNKNOWN http://www.vsecurity.com/resources/advisory/20100816-1/ Source: XF Type: UNKNOWN coda-ioctl-information-disclosure(61320) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |