PT-2013-1101 · Linux+2 · Linux Kernel+2

Theodore Tso

·

Publicado

2013-02-18

·

Atualizado

2023-02-13

·

CVE-2013-2015

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.7.3
Description The issue allows physically proximate attackers to cause a denial of service (system hang) via a crafted filesystem on removable media. This is due to the ext4 orphan del function in fs/ext4/namei.c not properly handling orphan-list entries for non-journal filesystems. Multiple vulnerabilities in the Linux package of the Debian GNU/Linux operating system can be exploited by a local attacker, potentially leading to breaches of confidentiality, integrity, and availability of protected information.
Recommendations For Linux kernel versions prior to 3.7.3, update to version 3.7.3 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for other affected versions.

Correção

DoS

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03064
CVE-2013-2015
DSA-2668-1
DSA-2669-1
MGASA-2013-0342
MGASA-2013-0343
MGASA-2013-0344
MGASA-2013-0345
MGASA-2013-0346
SUSE-SU-2015:0652-1
SUSE-SU-2016:2074-1

Produtos afetados

Debian
Linux Kernel
Suse