PT-2013-3614 · Linux+1 · Linux Kernel+1

Jonathan Salwan

·

Publicado

2013-11-12

·

Atualizado

2014-02-07

·

CVE-2013-2239

CVSS v2.0

4.7

Média

VetorAV:L/AC:M/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenVZ modification for the Linux kernel version 2.6.32, specifically vzkernel before 042stab080.2
Description The issue allows local users to obtain sensitive information from kernel stack memory. This can be achieved via a crafted ploop driver ioctl call, related to the ploop getdevice ioc function in drivers/block/ploop/dev.c, or a crafted quotactl system call, related to the compat quotactl function in fs/quota/quota.c.
Recommendations For vzkernel before 042stab080.2, update to version 042stab080.2 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-2239
DSA-2766-1

Produtos afetados

Linux Kernel
Openvz