CVE-2010-3310

Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 29 Sept 2010, 16:00
Last modified:07 Aug 2024, 03:03

Vulnerability Summary

Overall Risk (default)
minimal
8/100
CVSS Score
1.9 LOW
v2.0 (nvd)
EPSS Score
0.13% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

29 Sept 2010, 16:00
Published
Vulnerability first disclosed
07 Aug 2024, 03:03
Last Modified
Vulnerability information updated

Description

Multiple integer signedness errors in net/rose/af_rose.c in the Linux kernel before 2.6.36-rc5-next-20100923 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a rose_getname function call, related to the rose_bind and rose_connect functions.

CVSS Metrics

  • v2.0LOWScore: 1.9AV:L/AC:M/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 0.13% Percentile: 31%

Techniques & Countermeasures

  • CWE-189Numeric Errors

    Weaknesses in this category are related to improper calculation or conversion of numbers.

Affected Systems

  • canonicalubuntu_linux

    6.06 | 8.04 | 9.04 | 9.10 | 10.04 | 10.10

  • debiandebian_linux

    5.0

  • linuxlinux_kernel

    ≤ 2.6.36 | 2.6.36:rc1 | 2.6.36:rc2 | 2.6.36:rc3 | 2.6.36:rc4

References (22)