Vulnerability Description
Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Ubuntu Linux | 14.04 |
| Intel | Atom E3805 | - |
| Intel | Atom E3815 | - |
| Intel | Atom E3825 | - |
| Intel | Atom E3826 | - |
| Intel | Atom E3827 | - |
| Intel | Atom E3845 | - |
| Intel | Atom E620 | - |
| Intel | Atom E620T | - |
| Intel | Atom E640 | - |
| Intel | Atom E640T | - |
| Intel | Atom E660 | - |
| Intel | Atom E660T | - |
| Intel | Atom E680 | - |
| Intel | Atom E680T | - |
| Intel | Atom X3-C3130 | - |
| Intel | Atom X3-C3200Rk | - |
| Intel | Atom X3-C3230Rk | - |
| Intel | Atom X3-C3405 | - |
| Intel | Atom X3-C3445 | - |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html
- http://packetstormsecurity.com/files/156185/Kernel-Live-Patch-Security-Notice-LSThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/156455/Kernel-Live-Patch-Security-Notice-LS
- http://seclists.org/fulldisclosure/2020/Mar/31
- https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html
- https://support.apple.com/kb/HT211100
- https://usn.ubuntu.com/4253-1/Third Party Advisory
- https://usn.ubuntu.com/4253-2/Third Party Advisory
- https://usn.ubuntu.com/4254-1/Third Party Advisory
- https://usn.ubuntu.com/4254-2/Third Party Advisory
- https://usn.ubuntu.com/4255-1/Third Party Advisory
- https://usn.ubuntu.com/4255-2/Third Party Advisory
- https://usn.ubuntu.com/4284-1/
- https://usn.ubuntu.com/4285-1/
- https://usn.ubuntu.com/4286-1/
FAQ
What is CVE-2019-14615?
CVE-2019-14615 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via lo...
How severe is CVE-2019-14615?
CVE-2019-14615 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-14615?
Check the references section above for vendor advisories and patch information. Affected products include: Canonical Ubuntu Linux, Intel Atom E3805, Intel Atom E3815, Intel Atom E3825, Intel Atom E3826.