PT-2013-1022 · Linux+2 · Linux Kernel+2

Prasad Pandit

·

Publicado

2013-06-07

·

Atualizado

2018-01-09

·

CVE-2013-2147

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.9.4
Description The issue allows local users to obtain sensitive information from kernel memory. This is achieved through either a crafted IDAGETPCIINFO command for a /dev/ida device, related to the ida locked ioctl function in drivers/block/cpqarray.c, or a crafted CCISS PASSTHRU32 command for a /dev/cciss device, related to the cciss ioctl32 passthru function in drivers/block/cciss.c.
Recommendations For Linux kernel versions prior to 3.9.4, update to version 3.9.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the /dev/ida and /dev/cciss devices to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2014-00086
CVE-2013-2147
DSA-2906-1
MGASA-2013-0371
MGASA-2013-0372
MGASA-2013-0373
MGASA-2013-0374
MGASA-2013-0375
RHSA-2013:1166
RHSA-2013:1264
RHSA-2013_1166
SUSE-SU-2015:0652-1
USN-1994-1
USN-1996-1
USN-1997-1
USN-1999-1
USN-2015-1
USN-2016-1
USN-2017-1
USN-2018-1
USN-2020-1
USN-2023-1
USN-2050-1

Produtos afetados

Linux Kernel
Red Hat
Suse