Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2012-3520


The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Avahi or (2) NetworkManager.


Published

2012-10-03T11:02:57.143

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 1.9 (LOW)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

3.4

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System linux linux_kernel ≤ 3.2.29 Yes
Operating System linux linux_kernel 2.3.2 Yes
Operating System linux linux_kernel 2.3.20 Yes
Operating System linux linux_kernel 2.3.21 Yes
Operating System linux linux_kernel 2.3.22 Yes
Operating System linux linux_kernel 2.3.23 Yes
Operating System linux linux_kernel 2.3.24 Yes
Operating System linux linux_kernel 2.3.25 Yes
Operating System linux linux_kernel 2.3.26 Yes
Operating System linux linux_kernel 2.3.27 Yes
Operating System linux linux_kernel 2.3.28 Yes
Operating System linux linux_kernel 2.3.29 Yes
Operating System linux linux_kernel 2.4.33.2 Yes
Operating System linux linux_kernel 2.6.13.2 Yes
Operating System linux linux_kernel 2.6.23.2 Yes
Operating System linux linux_kernel 2.6.33.2 Yes
Operating System linux linux_kernel 2.6.33.20 Yes
Operating System linux linux_kernel 3.2 Yes
Operating System linux linux_kernel 3.2 Yes
Operating System linux linux_kernel 3.2 Yes
Operating System linux linux_kernel 3.2 Yes
Operating System linux linux_kernel 3.2 Yes
Operating System linux linux_kernel 3.2 Yes
Operating System linux linux_kernel 3.2 Yes
Operating System linux linux_kernel 3.2.1 Yes
Operating System linux linux_kernel 3.2.2 Yes
Operating System linux linux_kernel 3.2.3 Yes
Operating System linux linux_kernel 3.2.4 Yes
Operating System linux linux_kernel 3.2.5 Yes
Operating System linux linux_kernel 3.2.6 Yes
Operating System linux linux_kernel 3.2.7 Yes
Operating System linux linux_kernel 3.2.8 Yes
Operating System linux linux_kernel 3.2.9 Yes
Operating System linux linux_kernel 3.2.10 Yes
Operating System linux linux_kernel 3.2.11 Yes
Operating System linux linux_kernel 3.2.12 Yes
Operating System linux linux_kernel 3.2.13 Yes
Operating System linux linux_kernel 3.2.14 Yes
Operating System linux linux_kernel 3.2.15 Yes
Operating System linux linux_kernel 3.2.16 Yes
Operating System linux linux_kernel 3.2.17 Yes
Operating System linux linux_kernel 3.2.18 Yes
Operating System linux linux_kernel 3.2.19 Yes
Operating System linux linux_kernel 3.2.20 Yes
Operating System linux linux_kernel 3.2.21 Yes
Operating System linux linux_kernel 3.2.22 Yes
Operating System linux linux_kernel 3.2.23 Yes
Operating System linux linux_kernel 3.2.24 Yes
Operating System linux linux_kernel 3.2.25 Yes
Operating System linux linux_kernel 3.2.26 Yes
Operating System linux linux_kernel 3.2.27 Yes
Operating System linux linux_kernel 3.2.28 Yes
Operating System linux linux_kernel 3.3.2 Yes

References