PT-2013-1099 · Linux+3 · Linux Kernel+3
Brad Spengler
+2
·
Publicado
2013-02-18
·
Atualizado
2023-02-13
·
CVE-2013-1929
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 3.8.6
Description
The issue concerns multiple vulnerabilities in the Linux operating system, specifically in the Debian GNU/Linux package, which can be exploited by a local attacker to compromise the confidentiality, integrity, and availability of protected information. A heap-based buffer overflow vulnerability exists in the
tg3 read vpd function in the Linux kernel, allowing physically proximate attackers to cause a denial of service or possibly execute arbitrary code via crafted firmware.Recommendations
For Linux kernel versions prior to 3.8.6, update to version 3.8.6 or later to resolve the issue.
As a temporary workaround, consider restricting physical access to the system to minimize the risk of exploitation.
Exploit
Correção
DoS
Buffer Overflow
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Centos
Linux Kernel
Red Hat
Suse