CVE-2005-3276: Low severity Linux Linux kernel vulnerability
Published Oct 20, 2005
·Updated
The sysgetthreadarea function in process.c in Linux 2.6 before 2.6.12.4 and 2.6.13 does not clear a data structure before copying it to userspace, which might allow a user process to obtain sensitive information.
Affected Software
31 affected components
Linux Linux kernel=2.6.11
Linux Linux kernel=2.6.11.2
Linux Linux kernel=2.6.5
Linux Linux kernel=2.6.11.10
Linux Linux kernel=2.6.1
Linux Linux kernel=2.6.13
Linux Linux kernel=2.6.11.8
Linux Linux kernel=2.6.10
Linux Linux kernel=2.6.11.6
Linux Linux kernel=2.6.11.11
Linux Linux kernel=2.6.3
Linux Linux kernel=2.6.4
Linux Linux kernel=2.6.11.5
Linux Linux kernel=2.6.2
Linux Linux kernel=2.6.8
Linux Linux kernel=2.6.12.1
Linux Linux kernel=2.6.11.9
Linux Linux kernel=2.6.0
Linux Linux kernel=2.6.12.2
Linux Linux kernel=2.6.12.4
Linux Linux kernel=2.6.11.3
Linux Linux kernel=2.6.12.3
Linux Linux kernel=2.6.7
Linux Linux kernel=2.6.9-2.6.20
Linux Linux kernel=2.6.11.7
Linux Linux kernel=2.6.8.1
Linux Linux kernel=2.6.11.4
Linux Linux kernel=2.6.11.12
Linux Linux kernel=2.6.11.1
Linux Linux kernel=2.6.6
Linux Linux kernel=2.6.12
Remediation
Event History
Oct 20, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3276?
CVE-2005-3276 is considered to be of medium severity due to its ability to expose sensitive information.
2
How does CVE-2005-3276 affect Linux systems?
CVE-2005-3276 allows user processes to potentially access uninitialized memory data structures, leading to leakage of sensitive information.
3
What versions of Linux are affected by CVE-2005-3276?
CVE-2005-3276 affects Linux kernel versions from 2.6.0 up to and including 2.6.12.4 and 2.6.13.
4
How do I fix CVE-2005-3276?
To fix CVE-2005-3276, upgrade your Linux kernel to version 2.6.12.4 or later.
5
Is CVE-2005-3276 a common vulnerability in Linux?
CVE-2005-3276 is not common, but it is notable due to its implications on user data privacy.