CVE-2010-3437
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2010-3437 from the MITRE CVE dictionary dictionary and NIST NVD.
Statement
The Linux kernel as shipped with Red Hat Enterprise Linux 3 and 4 did not include support for Packet writing layer for ATAPI and SCSI disc media devices, and therefore are not affected by this issue. The Linux kernel as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG only allow root access to the "/dev/pktcdvd/control" file, and therefore are also not affected by this issue.
CVSS v2 metrics
| Base Score | 4.7 |
|---|---|
| Base Metrics | AV:L/AC:M/Au:N/C:C/I:N/A:N |
| Access Vector | Local |
| Access Complexity | Medium |
| Authentication | None |
| Confidentiality Impact | Complete |
| Integrity Impact | None |
| Availability Impact | None |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Red Hat Security Errata
| Platform | Errata | Release Date |
|---|---|---|
| Red Hat Enterprise Linux 6 (kernel) | RHSA-2010:0842 | 2010-11-10 |
Acknowledgements
Red Hat would like to thank Dan Rosenberg for reporting this issue.CVE description copyright © 2017, The MITRE Corporation
