PT-2013-3611 · Linux+4 · Linux Kernel+4

Prasad Pandit

·

Publicado

2013-07-04

·

Atualizado

2023-02-13

·

CVE-2013-2234

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.10
Description The issue affects the Linux kernel, where the key notify sa flush and key notify policy flush functions in net/key/af key.c do not properly initialize certain structure members. This allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify interface of an IPSec key socket.
Recommendations For Linux kernel versions prior to 3.10, update to version 3.10 or later to resolve the issue.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2013-1178
CESA-2013_1645
CVE-2013-2234
DSA-2745-1
DSA-2766-1
MGASA-2013-0203
MGASA-2013-0204
MGASA-2013-0209
MGASA-2013-0211
MGASA-2013-0212
MGASA-2013-0213
MGASA-2013-0215
RHSA-2013:1166
RHSA-2013:1264
RHSA-2013:1645
RHSA-2013_1166
RHSA-2013_1645
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0652-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-1912-1
USN-1913-1
USN-1938-1
USN-1941-1
USN-1942-1
USN-1943-1
USN-1944-1
USN-1945-1
USN-1946-1
USN-1947-1

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse