Uninitialized Memory Information Disclosure Vulnerability
CVE-2021-34999
5.5MEDIUM
What is CVE-2021-34999?
The OpenBSD Kernel contains a vulnerability in its multicast routing implementation, leading to the potential disclosure of sensitive information. This issue arises from uninitialized memory being accessed, which can be exploited by local attackers with low-privileged code execution rights. By leveraging this flaw in conjunction with other vulnerabilities, it may be possible for attackers to escalate their privileges and execute arbitrary code within the kernel context, posing significant security risks to the integrity of the system.
Affected Version(s)
Kernel OpenBSD 6.9
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved