PT-2013-1099 · Linux+3 · Linux Kernel+3

Brad Spengler

+2

·

Publicado

2013-02-18

·

Atualizado

2023-02-13

·

CVE-2013-1929

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.8.6
Description The issue concerns multiple vulnerabilities in the Linux operating system, specifically in the Debian GNU/Linux package, which can be exploited by a local attacker to compromise the confidentiality, integrity, and availability of protected information. A heap-based buffer overflow vulnerability exists in the tg3 read vpd function in the Linux kernel, allowing physically proximate attackers to cause a denial of service or possibly execute arbitrary code via crafted firmware.
Recommendations For Linux kernel versions prior to 3.8.6, update to version 3.8.6 or later to resolve the issue. As a temporary workaround, consider restricting physical access to the system to minimize the risk of exploitation.

Exploit

Correção

DoS

Buffer Overflow

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03064
CESA-2013_1645
CVE-2013-1929
DSA-2668-1
DSA-2669-1
RHSA-2013:0829
RHSA-2013:1034
RHSA-2013:1645
RHSA-2013_1034
RHSA-2013_1645
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-1833-1
USN-1834-1
USN-1835-1
USN-1836-1
USN-1838-1
USN-1839-1

Produtos afetados

Centos
Linux Kernel
Red Hat
Suse