CVE-2009-3238 Vulnerability Details

  /     /     /  

CVE-2009-3238 Metadata Quick Info

CVE Published: 18/09/2009 | CVE Updated: 07/08/2024 | CVE Year: 2009
Source: mitre | Vendor: n/a | Product: n/a
Status : PUBLISHED

CVE-2009-3238 Description

The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat protection mechanisms based on randomization, via vectors that leverage the function\'s tendency to "return the same value over and over again for long stretches of time."

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: n/a
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).