Vulnerability Name:

CVE-2012-4530 (CCN-79201)

Assigned:2012-08-18
Published:2012-08-18
Updated:2023-02-13
Summary:The load_script function in fs/binfmt_script.c in the Linux kernel before 3.7.2 does not properly handle recursion, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (REDHAT CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
1.6 Low (REDHAT Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2012-4530

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: Packetstorm Security Website
Linux binfmt_script Disclosure

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: RHSA-2013-0566
Important: kernel-rt security and bug fix update

Source: CCN
Type: The Linux Kernel Archives Web site
The Linux Kernel Archives

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: BID-55878
Linux Kernel 'binfmt_script.c' Local Information Disclosure Vulnerability

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: XF
Type: UNKNOWN
kernel-binfmtscript-info-disc(79201)

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:6:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:6::client:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:6::computenode:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:6::server:*:*:*:*:*
  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:6::workstation:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:accelatech:bizsearch:3.2:-:*:*:*:linux_kernel:*:*
  • AND
  • cpe:/o:redhat:enterprise_mrg:2.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20124530
    V
    CVE-2012-4530
    2022-05-20
    oval:org.opensuse.security:def:33115
    P
    Security update for libsndfile (Important)
    2022-01-05
    oval:org.opensuse.security:def:33066
    P
    Security update for chrony (Moderate)
    2021-12-22
    oval:org.opensuse.security:def:33009
    P
    Security update for MozillaFirefox (Important)
    2021-09-22
    oval:org.opensuse.security:def:33898
    P
    Security update for gdm (Important)
    2021-04-28
    oval:org.opensuse.security:def:29128
    P
    Security update for the Linux Kernel (Critical)
    2020-12-01
    oval:org.opensuse.security:def:28676
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:32391
    P
    Security update for tomcat6 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29810
    P
    Security update for jakarta
    2020-12-01
    oval:org.opensuse.security:def:28817
    P
    Security update for Python
    2020-12-01
    oval:org.opensuse.security:def:32480
    P
    MozillaFirefox on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28380
    P
    Security update for rubygem-actionpack-3_2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33177
    P
    librpcsecgss on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29023
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:32709
    P
    libexif on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28392
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:33859
    P
    Security update for jakarta-commons-collections (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29111
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:32853
    P
    emacs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28591
    P
    Security update for OpenSSH
    2020-12-01
    oval:org.opensuse.security:def:32390
    P
    Security update for tomcat6 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29172
    P
    Security update for microcode_ctl (Important)
    2020-12-01
    oval:org.opensuse.security:def:28733
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:32402
    P
    Security update for vim (Important)
    2020-12-01
    oval:org.opensuse.security:def:29846
    P
    Security update for Linux kernel
    2020-12-01
    oval:org.opensuse.security:def:33154
    P
    libgtop on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28969
    P
    Security update for orca (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32615
    P
    xdg-utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28381
    P
    Security update for rubygem-actionpack-3_2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:33221
    P
    pam on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29072
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:32766
    P
    pcsc-ccid on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28460
    P
    Security update for xorg-x11-libICE (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:24665
    P
    SUSE-SU-2014:0287-1 -- Security update for Linux kernel
    2015-03-16
    oval:org.mitre.oval:def:27657
    P
    ELSA-2013-2504 -- Unbreakable Enterprise kernel security update (moderate)
    2015-03-16
    oval:org.mitre.oval:def:27517
    P
    ELSA-2013-2503 -- Unbreakable Enterprise kernel security update (moderate)
    2014-12-15
    oval:org.mitre.oval:def:25739
    P
    SUSE-SU-2013:1832-1 -- Security update for Linux kernel
    2014-09-08
    oval:org.mitre.oval:def:25948
    P
    SUSE-SU-2013:0674-1 -- Security update for Linux kernel
    2014-09-08
    oval:org.mitre.oval:def:26226
    P
    SUSE-SU-2013:0259-1 -- kernel update for SLE11 SP2
    2014-09-08
    oval:org.mitre.oval:def:17933
    P
    USN-1691-1 -- linux-ti-omap4 vulnerability
    2014-07-21
    oval:org.mitre.oval:def:18273
    P
    USN-1683-1 -- linux vulnerability
    2014-07-21
    oval:org.mitre.oval:def:17337
    P
    USN-1696-1 -- linux vulnerabilities
    2014-07-07
    oval:org.mitre.oval:def:18072
    P
    USN-1684-1 -- linux-ec2 vulnerability
    2014-06-30
    oval:org.mitre.oval:def:17779
    P
    USN-1700-1 -- linux-ti-omap4 vulnerabilities
    2014-06-30
    oval:org.mitre.oval:def:18283
    P
    USN-1689-1 -- linux vulnerabilities
    2014-06-30
    oval:org.mitre.oval:def:17314
    P
    USN-1699-1 -- linux vulnerabilities
    2014-06-30
    oval:org.mitre.oval:def:18124
    P
    USN-1699-2 -- linux regression
    2014-06-30
    oval:org.mitre.oval:def:17858
    P
    USN-1700-2 -- linux-ti-omap4 regression
    2014-06-30
    oval:org.mitre.oval:def:18011
    P
    USN-1698-2 -- linux-ti-omap4 regression
    2014-06-30
    oval:org.mitre.oval:def:18254
    P
    USN-1704-1 -- linux-lts-quantal - Linux kernel hardware enablement from Quantal vulnerabilities
    2014-06-30
    oval:org.mitre.oval:def:17884
    P
    USN-1688-1 -- linux-lts-backport-oneiric vulnerabilities
    2014-06-30
    oval:org.mitre.oval:def:18036
    P
    USN-1704-2 -- linux-lts-quantal - Linux kernel hardware enablement from Quantal regression
    2014-06-30
    oval:org.mitre.oval:def:17680
    P
    USN-1698-1 -- linux-ti-omap4 vulnerabilities
    2014-06-30
    oval:org.mitre.oval:def:17894
    P
    USN-1696-2 -- linux regression
    2014-06-30
    oval:org.mitre.oval:def:23832
    P
    ELSA-2013:0223: kernel security and bug fix update (Moderate)
    2014-05-26
    oval:org.mitre.oval:def:20850
    P
    RHSA-2013:0223: kernel security and bug fix update (Moderate)
    2014-02-17
    oval:com.ubuntu.xenial:def:201245300000000
    V
    CVE-2012-4530 on Ubuntu 16.04 LTS (xenial) - low.
    2013-02-18
    oval:com.ubuntu.precise:def:20124530000
    V
    CVE-2012-4530 on Ubuntu 12.04 LTS (precise) - low.
    2013-02-17
    oval:com.ubuntu.trusty:def:20124530000
    V
    CVE-2012-4530 on Ubuntu 14.04 LTS (trusty) - low.
    2013-02-17
    oval:com.ubuntu.xenial:def:20124530000
    V
    CVE-2012-4530 on Ubuntu 16.04 LTS (xenial) - low.
    2013-02-17
    oval:com.redhat.rhsa:def:20130223
    P
    RHSA-2013:0223: kernel security and bug fix update (Moderate)
    2013-02-05
    BACK
    accelatech bizsearch 3.2 -
    redhat enterprise mrg 2.0