PT-2011-5230 · Red Hat+5 · Systemtap-Runtime-Debuginfo+20

Andrew Honig

·

Publicado

1970-01-01

·

Atualizado

2023-02-13

·

CVE-2013-1798

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions openSUSE versions prior to the fixed version Linux kernel versions through 3.8.4 systemtap versions (affected versions not specified) systemtap-runtime versions (affected versions not specified) systemtap-runtime-debuginfo versions (affected versions not specified) systemtap-server versions (affected versions not specified) systemtap-server-debuginfo versions (affected versions not specified) systemtap-client versions (affected versions not specified) systemtap-client-debuginfo versions (affected versions not specified) systemtap-sdt-devel versions (affected versions not specified) libvmtools0 versions (affected versions not specified) libvmtools0-debuginfo versions (affected versions not specified) kernel-vanilla-base versions (affected versions not specified) kernel-vanilla-base-debuginfo versions (affected versions not specified) systemtap-debuginfo versions (affected versions not specified) systemtap-debugsource versions (affected versions not specified) libvmtools-devel versions (affected versions not specified)
Description The issue involves multiple vulnerabilities in various packages of the openSUSE operating system and the Linux kernel, which can lead to disruption of protected information availability. These vulnerabilities can be exploited remotely or locally, depending on the specific package and version. The ioapic read indirect function in the Linux kernel does not properly handle certain combinations of invalid IOAPIC REG SELECT and IOAPIC REG WINDOW operations, allowing guest OS users to obtain sensitive information from host OS memory or cause a denial of service.
Recommendations For Linux kernel versions through 3.8.4, update to a version later than 3.8.4 to resolve the issue. For systemtap and its related packages, there is no information about a newer version that contains a fix for this vulnerability. For kernel-vanilla-base and its related packages, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to vulnerable packages and modules to minimize the risk of exploitation. Avoid using vulnerable functions and parameters in affected API endpoints until the issue is resolved.

Exploit

DoS

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2013-1178
ALT-PU-2020-1204
ALT-PU-2020-1219
ALT-PU-2020-1398
ALT-PU-2020-1501
ALT-PU-2020-1524
ALT-PU-2020-1945
ALT-PU-2020-3057
ALT-PU-2021-1745
BDU:2015-05303
BDU:2015-05304
BDU:2015-05305
BDU:2015-05306
BDU:2015-05307
BDU:2015-05308
BDU:2015-05309
BDU:2015-05310
BDU:2015-05311
BDU:2015-05312
BDU:2015-05313
BDU:2015-05314
BDU:2015-05315
BDU:2015-05542
BDU:2015-05543
CESA-2013_0744
CVE-2013-1798
DSA-2668-1
LSN-0065-1
OPENSUSE-SU-2013_0847-1
OPENSUSE-SU-2013_0925-1
OPENSUSE-SU-2013_1187-1
RHSA-2013:0727
RHSA-2013:0744
RHSA-2013:0746
RHSA-2013:0928
RHSA-2013:1026
RHSA-2013_0727
RHSA-2013_0744
SUSE-SU-2015:0481-1
SUSE-SU-2015:0652-1
USN-1809-1
USN-1812-1
USN-1813-1
USN-1876-1
USN-1877-1

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Kernel-Vanilla-Base
Kernel-Vanilla-Base-Debuginfo
Libvmtools-Devel
Libvmtools0
Libvmtools0-Debuginfo
Opensuse
Systemtap
Systemtap-Client
Systemtap-Client-Debuginfo
Systemtap-Debuginfo
Systemtap-Debugsource
Systemtap-Runtime
Systemtap-Runtime-Debuginfo
Systemtap-Sdt-Devel
Systemtap-Server
Systemtap-Server-Debuginfo