PT-2013-1100 · Debian+2 · Debian+2
Andy Lutomirski
·
Publicado
2013-02-18
·
Atualizado
2023-02-13
·
CVE-2013-1979
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Debian GNU/Linux versions prior to 3.8.11
Linux kernel versions prior to 3.8.11
Description
The issue concerns multiple vulnerabilities in the Linux package of the Debian GNU/Linux operating system, which can be exploited by a local attacker to compromise the confidentiality, integrity, and availability of protected information. A specific problem is identified in the
scm set cred function, where incorrect uid and gid values are used during credentials passing, allowing local users to gain privileges via a crafted application.Recommendations
For Debian GNU/Linux versions prior to 3.8.11, update to version 3.8.11 or later to resolve the issue.
For Linux kernel versions prior to 3.8.11, update to version 3.8.11 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
scm set cred function until a patch is available.Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Debian
Linux Kernel
Suse