UBUNTU-CVE-2011-2492
Dashboard / Vulnerabilities / UBUNTU-CVE-2011-2492
UBUNTU-CVE-2011-2492
Summary:
Details: The bluetooth subsystem in the Linux kernel before 3.0-rc4 does not properly initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel memory via a crafted getsockopt system call, related to (1) the l2cap_sock_getsockopt_old function in net/bluetooth/l2cap_sock.c and (2) the rfcomm_sock_getsockopt_old function in net/bluetooth/rfcomm/sock.c.
References: https://ubuntu.com/security/CVE-2011-2492, https://ubuntu.com/security/notices/USN-1189-1, https://ubuntu.com/security/notices/USN-1202-1, https://ubuntu.com/security/notices/USN-1205-1, https://ubuntu.com/security/notices/USN-1201-1, https://ubuntu.com/security/notices/USN-1204-1, https://ubuntu.com/security/notices/USN-1203-1, https://ubuntu.com/security/notices/USN-1208-1, https://ubuntu.com/security/notices/USN-1212-1, https://ubuntu.com/security/notices/USN-1211-1, https://ubuntu.com/security/notices/USN-1216-1, https://ubuntu.com/security/notices/USN-1218-1, https://ubuntu.com/security/notices/USN-1256-1, https://www.cve.org/CVERecord?id=CVE-2011-2492
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
