PT-2013-3614 · Linux+1 · Linux Kernel+1
Jonathan Salwan
·
Publicado
2013-11-12
·
Atualizado
2014-02-07
·
CVE-2013-2239
CVSS v2.0
4.7
Média
| Vetor | AV:L/AC:M/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenVZ modification for the Linux kernel version 2.6.32, specifically vzkernel before 042stab080.2
Description
The issue allows local users to obtain sensitive information from kernel stack memory. This can be achieved via a crafted ploop driver ioctl call, related to the
ploop getdevice ioc function in drivers/block/ploop/dev.c, or a crafted quotactl system call, related to the compat quotactl function in fs/quota/quota.c.Recommendations
For vzkernel before 042stab080.2, update to version 042stab080.2 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Linux Kernel
Openvz