VulnerabilityModified
CVE-2005-3257
The VT implementation (vt_ioctl.c) in Linux kernel 2.6.12, and possibly other versions including 2.6.14.4, allows local users to use the KDSKBSENT ioctl on terminals of other users and gain privileges, as demonstrated by modifying key bindings using…
MEDIUM 4.6EPSS 1.06%
Does this matter?
Lower severity and a low EPSS score (1.06%). Track it; it rarely justifies an emergency change on its own.
Description
The VT implementation (vt_ioctl.c) in Linux kernel 2.6.12, and possibly other versions including 2.6.14.4, allows local users to use the KDSKBSENT ioctl on terminals of other users and gain privileges, as demonstrated by modifying key bindings using loadkeys.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.06% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- linux/linux kernel
- Source
- cve@mitre.org
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=334113Exploit, Vendor Advisory
- http://rhn.redhat.com/errata/RHBA-2007-0304.html
- http://secunia.com/advisories/17226Vendor Advisory
- http://secunia.com/advisories/17826Vendor Advisory
- http://secunia.com/advisories/17995Vendor Advisory
- http://secunia.com/advisories/18203Vendor Advisory
- http://secunia.com/advisories/19185Vendor Advisory
- http://secunia.com/advisories/19369Vendor Advisory
- http://secunia.com/advisories/19374Vendor Advisory
- http://www.debian.org/security/2006/dsa-1017
- http://www.debian.org/security/2006/dsa-1018
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:218
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:219
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:220
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:235
- http://www.securityfocus.com/bid/15122
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10615
- https://usn.ubuntu.com/231-1/
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=334113Exploit, Vendor Advisory
- http://rhn.redhat.com/errata/RHBA-2007-0304.html
- http://secunia.com/advisories/17226Vendor Advisory
- http://secunia.com/advisories/17826Vendor Advisory
- http://secunia.com/advisories/17995Vendor Advisory
- http://secunia.com/advisories/18203Vendor Advisory
- http://secunia.com/advisories/19185Vendor Advisory
- http://secunia.com/advisories/19369Vendor Advisory
- http://secunia.com/advisories/19374Vendor Advisory
- http://www.debian.org/security/2006/dsa-1017
- http://www.debian.org/security/2006/dsa-1018
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:218
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.