PT-2013-1100 · Debian+2 · Debian+2

Andy Lutomirski

·

Publicado

2013-02-18

·

Atualizado

2023-02-13

·

CVE-2013-1979

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Debian GNU/Linux versions prior to 3.8.11 Linux kernel versions prior to 3.8.11
Description The issue concerns multiple vulnerabilities in the Linux package of the Debian GNU/Linux operating system, which can be exploited by a local attacker to compromise the confidentiality, integrity, and availability of protected information. A specific problem is identified in the scm set cred function, where incorrect uid and gid values are used during credentials passing, allowing local users to gain privileges via a crafted application.
Recommendations For Debian GNU/Linux versions prior to 3.8.11, update to version 3.8.11 or later to resolve the issue. For Linux kernel versions prior to 3.8.11, update to version 3.8.11 or later to resolve the issue. As a temporary workaround, consider restricting access to the scm set cred function until a patch is available.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03064
CVE-2013-1979
DSA-2669-1
RHSA-2013:0829
SUSE-RU-2015:0621-1
SUSE-SU-2014_1316-1
SUSE-SU-2014_1319-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
SUSE-SU-2019:14051-1
SUSE-SU-2019_14051-1
USN-1815-1
USN-1833-1
USN-1839-1
USN-1880-1
USN-1881-1
USN-1882-1
USN-1883-1

Produtos afetados

Debian
Linux Kernel
Suse