LOW · 2.6

CVE-2012-3368

Integer signedness error in attach.c in dtach 0.8 allows remote attackers to obtain sensitive information from daemon stack memory in opportunistic circumstances by reading application data after an i...

Vulnerability Description

Integer signedness error in attach.c in dtach 0.8 allows remote attackers to obtain sensitive information from daemon stack memory in opportunistic circumstances by reading application data after an improper connection-close request, as demonstrated by running an IRC client in dtach.

CVSS Score

2.6

LOW

AV:N/AC:H/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
RedhatDtach0.8

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-3368?

CVE-2012-3368 is a vulnerability with a CVSS score of 2.6 (LOW). Integer signedness error in attach.c in dtach 0.8 allows remote attackers to obtain sensitive information from daemon stack memory in opportunistic circumstances by reading application data after an i...

How severe is CVE-2012-3368?

CVE-2012-3368 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-3368?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat Dtach.