CVE-2014-1445
The wanxl_ioctl function in drivers/net/wan/wanxl.c in the Linux kernel before 3.11.7 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via an ioctl call.
- Affected products
- Alt Linux, Linux Kernel, Suse Linux Enterprise, Suse
- Linux Linux Kernel
- ≤ 3.11.6, 3.11, 3.11.1, 3.11.2, 3.11.3, 3.11.4, 3.11.5
- Fix
- Available
- CVSS 2.0
- 2.1 LOW
- EPSS
- 0.4% (34th percentile)
- Weakness
- CWE-399
- NVD status
- Modified
- Published
- 2014-01-18
CVE-2014-1445 at NVD
1 known exploit for CVE-2014-1445
Proof-of-concept code and exploit modules indexed by Sploitus