VulnerabilityModified
CVE-2019-14615
Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.
MEDIUM 5.5EPSS 1.45%
Does this matter?
Lower severity and a low EPSS score (1.45%). Track it; it rarely justifies an emergency change on its own.
Description
Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 1.45% probability · 72th percentile
- CISA KEV
- Not listed
- Affected
- canonical/ubuntu linux · intel/atom e3805 · intel/atom e3815 · intel/atom e3825 · intel/atom e3826 · intel/atom e3827 · intel/atom e3845 · intel/atom e620 · intel/atom e620t · intel/atom e640 · intel/atom e640t · intel/atom e660 · intel/atom e660t · intel/atom e680 · intel/atom e680t · intel/atom x3-c3130 · intel/atom x3-c3200rk · intel/atom x3-c3230rk · intel/atom x3-c3405 · intel/atom x3-c3445 · +40 more
- Source
- secure@intel.com
References
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html
- http://packetstormsecurity.com/files/156185/Kernel-Live-Patch-Security-Notice-LSN-0062-1.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/156455/Kernel-Live-Patch-Security-Notice-LSN-0063-1.html
- http://seclists.org/fulldisclosure/2020/Mar/31
- https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html
- https://support.apple.com/kb/HT211100
- https://usn.ubuntu.com/4253-1/Third Party Advisory
- https://usn.ubuntu.com/4253-2/Third Party Advisory
- https://usn.ubuntu.com/4254-1/Third Party Advisory
- https://usn.ubuntu.com/4254-2/Third Party Advisory
- https://usn.ubuntu.com/4255-1/Third Party Advisory
- https://usn.ubuntu.com/4255-2/Third Party Advisory
- https://usn.ubuntu.com/4284-1/
- https://usn.ubuntu.com/4285-1/
- https://usn.ubuntu.com/4286-1/
- https://usn.ubuntu.com/4286-2/
- https://usn.ubuntu.com/4287-1/
- https://usn.ubuntu.com/4287-2/
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00314.htmlVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html
- http://packetstormsecurity.com/files/156185/Kernel-Live-Patch-Security-Notice-LSN-0062-1.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/156455/Kernel-Live-Patch-Security-Notice-LSN-0063-1.html
- http://seclists.org/fulldisclosure/2020/Mar/31
- https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html
- https://support.apple.com/kb/HT211100
- https://usn.ubuntu.com/4253-1/Third Party Advisory
- https://usn.ubuntu.com/4253-2/Third Party Advisory
- https://usn.ubuntu.com/4254-1/Third Party Advisory
- https://usn.ubuntu.com/4254-2/Third Party Advisory
- https://usn.ubuntu.com/4255-1/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.