CVE-2009-1265
Integer overflow in rose_sendmsg (sys/net/af_rose.c) in the Linux kernel 2.6.24.4, and other versions before 2.6.30-rc1, might allow remote attackers to obtain sensitive information via a large length value, which causes "garbage" memory to be sent.
- Affected products
- Linux Kernel, Opensuse
- Linux Linux Kernel
- = 2.6.24.4, 2.6.24.5, 2.6.24.6, 2.6.24.7, 2.6.25, 2.6.25.1, 2.6.25.2, 2.6.25.3, 2.6.25.4, 2.6.25.5, 2.6.25.6, 2.6.25.7, 2.6.25.8, 2.6.25.9, 2.6.25.10, 2.6.25.11, 2.6.25.12, 2.6.25.13, 2.6.25.14, 2.6.25.15, 2.6.25.16, 2.6.25.17, 2.6.25.18, 2.6.25.19, 2.6.25.20, 2.6.26, 2.6.26.1, 2.6.26.2, 2.6.26.3, 2.6.26.4, 2.6.26.5, 2.6.26.6, 2.6.26.7, 2.6.27, 2.6.27.1, 2.6.27.2, 2.6.27.3, 2.6.27.4, 2.6.27.5, 2.6.27.6
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 3.2% (87th percentile)
- Weakness
- CWE-189
- NVD status
- Modified
- Published
- 2009-04-08
CVE-2009-1265 at NVD
1 known exploit for CVE-2009-1265
Proof-of-concept code and exploit modules indexed by Sploitus