LOW · 2.1

CVE-2014-1738

The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allow...

Vulnerability Description

The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kernel heap memory by leveraging write access to a /dev/fd device.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
LinuxLinux Kernel<= 3.14.3
RedhatEnterprise Linux Eus5.6
DebianDebian Linux6.0
OracleLinux5
SuseLinux Enterprise Desktop11
SuseLinux Enterprise High Availability Extension11
SuseLinux Enterprise Real Time Extension11
SuseLinux Enterprise Server11

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-1738?

CVE-2014-1738 is a vulnerability with a CVSS score of 2.1 (LOW). The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allow...

How severe is CVE-2014-1738?

CVE-2014-1738 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-1738?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Redhat Enterprise Linux Eus, Debian Debian Linux, Oracle Linux, Suse Linux Enterprise Desktop.