CVE-2010-3877 is a local information disclosure vulnerability in the Linux kernel, specifically affecting the get_name function in net/tipc/socket.c in versions prior to 2.6.37-rc2, including various Debian distributions. The vulnerability stems from an uninitialized structure, allowing local users to read sensitive data from kernel stack memory. With a CVSS score of 1.9 (low severity), exploitation requires local access and medium attack complexity, resulting in a potential impact of partial confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6.37CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
2.6.37CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.37:-:*:*:*:*:*:* | ||
2.6.37CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.37:rc1:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.