CVE-2012-1568

Public on 2012-03-23
Modified on 2014-09-14
Description
The ExecShield feature in a certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 5 and 6 and Fedora 15 and 16 does not properly handle use of many shared libraries by a 32-bit executable file, which makes it easier for context-dependent attackers to bypass the ASLR protection mechanism by leveraging a predictable base address for one of these libraries.
Severity
Low severity
Low
CVSS v3 Base Score
1.9
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 kernel 2012-11-20 ALAS-2012-142 Fixed
Amazon Linux 1 kernel 2012-03-23 ALAS-2012-58 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv2 1.9 AV:L/AC:M/Au:N/C:N/I:P/A:N
NVD CVSSv2 1.9 AV:L/AC:M/Au:N/C:N/I:P/A:N