PT-2013-1032 · Linux+4 · Linux Kernel+4

Prasad Pandit

·

Publicado

2013-11-19

·

Atualizado

2023-12-15

·

CVE-2013-6383

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.11.8
Description The issue allows local users to bypass intended access restrictions via a crafted ioctl call due to the lack of privilege level checking in the aac compat ioctl function. This could potentially lead to privilege escalation.
Recommendations For Linux kernel versions prior to 3.11.8, update to version 3.11.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the aac compat ioctl function to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2013-1133
ALT-PU-2014-1422
ALT-PU-2014-1606
BDU:2014-00099
CESA-2014_0475
CVE-2013-6383
DSA-2906-1
MGASA-2013-0371
MGASA-2013-0372
MGASA-2013-0373
MGASA-2013-0374
MGASA-2013-0375
RHSA-2014:0100
RHSA-2014:0285
RHSA-2014:0475
RHSA-2014:0476
RHSA-2014:0634
RHSA-2014_0285
RHSA-2014_0475
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0652-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2066-1
USN-2067-1
USN-2068-1
USN-2069-1
USN-2070-1
USN-2071-1
USN-2072-1
USN-2073-1
USN-2074-1
USN-2075-1
USN-2076-1
USN-2107-1
USN-2108-1

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse