CVE-2008-3895

EUVD-2008-3881
LILO 22.6.1 and earlier stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.1 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
Affected Products (NVD)
VendorProductVersion
lilolilo
𝑥
≤ 22.6.1
lilolilo
21.4.2
lilolilo
21.4.3
lilolilo
21.4.4
lilolilo
21.5
lilolilo
21.5.1
lilolilo
21.6
lilolilo
21.6.1
lilolilo
21.7
lilolilo
21.7.1
lilolilo
21.7.2
lilolilo
21.7.3
lilolilo
21.7.4
lilolilo
21.7.5
lilolilo
22.0
lilolilo
22.0.1
lilolilo
22.0.2
lilolilo
22.1
lilolilo
22.2
lilolilo
22.3
lilolilo
22.3.1
lilolilo
22.3.2
lilolilo
22.3.3
lilolilo
22.3.4
lilolilo
22.4
lilolilo
22.4.1
lilolilo
22.5
lilolilo
22.5.1
lilolilo
22.5.2
lilolilo
22.5.3
lilolilo
22.5.3.1
lilolilo
22.5.4
lilolilo
22.5.5
lilolilo
22.5.6
lilolilo
22.5.7
lilolilo
22.5.7.2
lilolilo
22.5.8
lilolilo
22.5.9
lilolilo
22.6
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
lilo
dapper
ignored
feisty
ignored
gutsy
ignored
hardy
ignored
intrepid
ignored
jaunty
ignored
karmic
ignored