PT-2013-3973 · Linux+3 · Linux Kernel+3
CVSS v2.0
6.9
Média
| Vetor | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions through 3.9.4
Description
The issue allows local users to gain privileges by leveraging root access and including format string specifiers in an
fwpostfix modprobe parameter, leading to improper construction of an error message in the b43 request firmware function. This is located in the Broadcom B43 wireless driver.Recommendations
For Linux kernel versions through 3.9.4, consider restricting access to the
b43 request firmware function until a patch is available. As a temporary workaround, avoid using the fwpostfix modprobe parameter with format string specifiers to minimize the risk of exploitation.Exploit
Correção
Use of Externally-Controlled Format String
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Linux Kernel
Red Hat
Suse