PT-2011-5209 · Linux+3 · Linux Kernel+3

Publicado

1970-01-01

·

Atualizado

2024-06-15

·

CVE-2013-0160

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 3.7.9
Description The issue allows local users to obtain sensitive information about keystroke timing by using the inotify API on the /dev/ptmx device. Multiple vulnerabilities in various packages of the openSUSE and Debian GNU/Linux operating systems can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally or remotely.
Recommendations For Linux kernel versions through 3.7.9: As a temporary workaround, consider restricting access to the /dev/ptmx device until a patch is available. Avoid using the inotify API on the /dev/ptmx device until the issue is resolved. For other affected packages in openSUSE and Debian GNU/Linux, restrict access to vulnerable components and apply configuration changes to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03064
BDU:2015-05303
BDU:2015-05304
BDU:2015-05305
BDU:2015-05306
BDU:2015-05307
BDU:2015-05308
BDU:2015-05309
BDU:2015-05310
BDU:2015-05311
BDU:2015-05312
BDU:2015-05313
BDU:2015-05314
BDU:2015-05315
CVE-2013-0160
DSA-2669-1
OPENSUSE-SU-2013_0395-1
OPENSUSE-SU-2013_0396-1
OPENSUSE-SU-2013_0925-1
OPENSUSE-SU-2013_1187-1
OPENSUSE-SU-2024:10128-1
SUSE-RU-2015:0621-1
SUSE-SU-2013_1022-2
SUSE-SU-2013_1022-3
SUSE-SU-2013_1182-2
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0652-1
SUSE-SU-2015:1174-1
SUSE-SU-2019:14051-1
SUSE-SU-2019_14051-1
USN-1878-1
USN-1879-1
USN-1880-1
USN-1881-1
USN-1882-1
USN-1883-1
USN-1916-1
USN-2128-1
USN-2129-1

Produtos afetados

Debian
Linux Kernel
Suse
Opensuse