PT-2013-5086 · Linux+3 · Linux Kernel+3

Petr Matousek

·

Publicado

2013-11-19

·

Atualizado

2023-02-13

·

CVE-2013-4591

CVSS v2.0

6.2

Média

VetorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.7.2
Description The issue is related to a buffer overflow in the nfs4 get acl uncached function, which can cause a denial of service, resulting in memory corruption and system crash. It may also have other unspecified impacts. This occurs when a local user makes a getxattr system call for the system.nfs4 acl extended attribute of a pathname on an NFSv4 filesystem.
Recommendations For Linux kernel versions prior to 3.7.2, update to version 3.7.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the nfs4 get acl uncached function or limiting the use of the getxattr system call for the system.nfs4 acl extended attribute on NFSv4 filesystems until the update is applied.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2013_1645
CVE-2013-4591
RHSA-2013:1645
RHSA-2013_1645
RHSA-2014:0284
SUSE-SU-2015:0652-1

Produtos afetados

Centos
Linux Kernel
Red Hat
Suse