Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2002-1571

Overview

Vulnerability Score 2.1 2.1
CVE Id CVE-2002-1571
Last Modified 05 Sep 2008 04:30:57
Published 31 Dec 2002 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2002-1571

Summary

The linux 2.4 kernel before 2.4.19 assumes that the fninit instruction clears all registers, which could lead to an information leak on processors that do not clear all relevant SSE registers.

Vulnerable Systems

Operating System

  • Linux Kernel 2.4.0

  • Linux Kernel 2.4.1

  • Linux Kernel 2.4.10

  • Linux Kernel 2.4.11

  • Linux Kernel 2.4.12

  • Linux Kernel 2.4.13

  • Linux Kernel 2.4.14

  • Linux Kernel 2.4.15

  • Linux Kernel 2.4.16

  • Linux Kernel 2.4.17

  • Linux Kernel 2.4.18

  • Linux Kernel 2.4.19

  • Linux Kernel 2.4.2

  • Linux Kernel 2.4.3

  • Linux Kernel 2.4.4

  • Linux Kernel 2.4.5

  • Linux Kernel 2.4.6

  • Linux Kernel 2.4.7

  • Linux Kernel 2.4.8

  • Linux Kernel 2.4.9


References

MLIST - [linux-kernel] 20020417 Re: SSE related security hole

MLIST - [linux-kernel] 20020417 SSE related security hole

MLIST - [linux-kernel] 20020422 Re: SSE related security hole

MLIST - [linux-kernel] 20020418 Re: SSE related security hole

CONFIRM - http://linux.bkbits.net:8080/linux-2.4/diffs/arch/i386/kernel/i387.c@1.6


Last Updated: 27 May 2016 10:37:24