The media_device_enum_entities function in drivers/media/media-device.c in the Linux kernel before 3.14.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging /dev/media0 read access for a MEDIA_IOC_ENUM_ENTITIES ioctl call.
http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.html
http://secunia.com/advisories/59597
http://speirofr.appspot.com/cve-2014-1739-kernel-infoleak-vulnerability-in-media_enum_entities.html
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.6
http://www.openwall.com/lists/oss-security/2014/06/15/1
http://www.securityfocus.com/bid/68048
http://www.securitytracker.com/id/1038201
http://www.ubuntu.com/usn/USN-2259-1
http://www.ubuntu.com/usn/USN-2261-1
http://www.ubuntu.com/usn/USN-2263-1
http://www.ubuntu.com/usn/USN-2264-1
https://bugzilla.redhat.com/show_bug.cgi?id=1109774
https://github.com/torvalds/linux/commit/e6a623460e5fc960ac3ee9f946d3106233fd28d8
OR
OR
OR
cpe:2.3:o:suse:linux_enterprise_high_availability_extension:11:sp3:*:*:*:*:*:*
cpe:2.3:o:suse:suse_linux_enterprise_desktop:11:sp3:*:*:*:*:*:*
cpe:2.3:o:suse:suse_linux_enterprise_server:11:sp3:*:*:*:-:*:*
cpe:2.3:o:suse:suse_linux_enterprise_server:11:sp3:*:*:*:vmware:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
124971 | EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1518) | Nessus | Huawei Local Security Checks | high |
124803 | EulerOS Virtualization 3.0.1.0 : kernel (EulerOS-SA-2019-1479) | Nessus | Huawei Local Security Checks | critical |
99163 | OracleVM 3.3 : Unbreakable / etc (OVMSA-2017-0057) (Dirty COW) | Nessus | OracleVM Local Security Checks | critical |
83633 | SUSE SLES11 Security Update : kernel (SUSE-SU-2014:1105-1) | Nessus | SuSE Local Security Checks | high |
81800 | Oracle Linux 7 : kernel (ELSA-2015-0290) | Nessus | Oracle Linux Local Security Checks | high |
80152 | openSUSE Security Update : the Linux Kernel (openSUSE-SU-2014:1677-1) | Nessus | SuSE Local Security Checks | high |
80014 | Scientific Linux Security Update : kernel on SL7.x x86_64 (20141209) | Nessus | Scientific Linux Local Security Checks | high |
80005 | Oracle Linux 5 / 6 : Unbreakable Enterprise kernel (ELSA-2014-3104) | Nessus | Oracle Linux Local Security Checks | medium |
79876 | CentOS 7 : kernel (CESA-2014:1971) | Nessus | CentOS Local Security Checks | high |
79848 | RHEL 7 : kernel (RHSA-2014:1971) | Nessus | Red Hat Local Security Checks | high |
79845 | Oracle Linux 7 : kernel (ELSA-2014-1971) | Nessus | Oracle Linux Local Security Checks | high |
79735 | Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2014-3096) | Nessus | Oracle Linux Local Security Checks | high |
78651 | SuSE 11.3 Security Update : Linux kernel (SAT Patch Number 9750) | Nessus | SuSE Local Security Checks | high |
78650 | SuSE 11.3 Security Update : Linux kernel (SAT Patch Numbers 9746 / 9749 / 9751) | Nessus | SuSE Local Security Checks | high |
78335 | Amazon Linux AMI : kernel (ALAS-2014-392) | Nessus | Amazon Linux Local Security Checks | high |
76569 | Ubuntu 14.04 LTS : linux vulnerabilities (USN-2290-1) | Nessus | Ubuntu Local Security Checks | high |
76567 | Ubuntu 12.04 LTS : linux-lts-trusty vulnerabilities (USN-2288-1) | Nessus | Ubuntu Local Security Checks | high |
76565 | Ubuntu 12.04 LTS : linux-lts-raring vulnerabilities (USN-2286-1) | Nessus | Ubuntu Local Security Checks | high |
76564 | Ubuntu 12.04 LTS : linux-lts-quantal vulnerabilities (USN-2285-1) | Nessus | Ubuntu Local Security Checks | high |
76298 | Ubuntu 13.10 : linux vulnerabilities (USN-2264-1) | Nessus | Ubuntu Local Security Checks | medium |
76296 | Ubuntu 12.04 LTS : linux-lts-saucy vulnerabilities (USN-2261-1) | Nessus | Ubuntu Local Security Checks | medium |
76294 | Ubuntu 12.04 LTS : linux vulnerabilities (USN-2259-1) | Nessus | Ubuntu Local Security Checks | medium |