CVE-2014-4027

Advisory lineage Upstream: 0 Downstream: 5
Modified
Published: 23 Jun 2014, 10:00
Last modified:06 Aug 2024, 11:04

Vulnerability Summary

Overall Risk (default)
minimal
9/100
CVSS Score
2.3 LOW
v2.0 (nvd)
EPSS Score
0.09% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Jun 2014, 10:00
Published
Vulnerability first disclosed
06 Aug 2024, 11:04
Last Modified
Vulnerability information updated

Description

The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from ramdisk_mcp memory by leveraging access to a SCSI initiator.

CVSS Metrics

  • v2.0LOWScore: 2.3AV:A/AC:M/Au:S/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.09% Percentile: 26%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • canonicalubuntu_linux

    12.04

  • f5big-ip_access_policy_manager

    ≥ 11.1.0, ≤ 11.6.0 | 12.0.0

  • f5big-ip_advanced_firewall_manager

    ≥ 11.3.0, ≤ 11.6.0 | 12.0.0

  • f5big-ip_analytics

    ≥ 11.1.0, ≤ 11.6.0 | 12.0.0

  • f5big-ip_application_acceleration_manager

    ≥ 11.4.0, ≤ 11.6.0 | 12.0.0

  • f5big-ip_application_security_manager

    ≥ 11.1.0, ≤ 11.6.0 | 12.0.0

  • f5big-ip_domain_name_system

    12.0.0

  • f5big-ip_edge_gateway

    ≥ 11.1.0, ≤ 11.3.0

  • f5big-ip_global_traffic_manager

    ≥ 11.1.0, ≤ 11.6.0

  • f5big-ip_link_controller

    ≥ 11.1.0, ≤ 11.6.0 | 12.0.0

  • f5big-ip_local_traffic_manager

    ≥ 11.1.0, ≤ 11.6.0 | 12.0.0

  • f5big-ip_policy_enforcement_manager

    ≥ 11.3.0, ≤ 11.6.0 | 12.0.0

  • f5big-ip_protocol_security_module

    ≥ 11.1.0, ≤ 11.4.1

  • f5big-ip_wan_optimization_manager

    ≥ 11.1.0, ≤ 11.3.0

  • f5big-ip_webaccelerator

    ≥ 11.1.0, ≤ 11.3.0

  • f5big-iq_application_delivery_controller

    4.5.0

  • f5big-iq_cloud

    ≥ 4.0.0, ≤ 4.5.0

  • f5big-iq_device

    ≥ 4.2.0, ≤ 4.5.0

  • f5big-iq_security

    ≥ 4.0.0, ≤ 4.5.0

  • f5enterprise_manager

    ≥ 3.0.0, ≤ 3.1.1

  • linuxlinux_kernel

    < 3.14

  • redhatenterprise_linux

    6.0

  • suselinux_enterprise_desktop

    11:sp3

  • suselinux_enterprise_high_availability_extension

    11:sp3

  • suselinux_enterprise_real_time_extension

    11:sp3

  • suselinux_enterprise_server

    11:sp3

References (14)