PT-2013-5169 · Linux · Linux Kernel

Jonathan Salwan

·

Publicado

2013-11-12

·

Atualizado

2013-11-14

·

CVE-2013-4740

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions 3.x
Description The issue relies on user-space length values for kernel-memory copies of procfs file content, allowing attackers to gain privileges or cause a denial of service (memory corruption) via an application that provides crafted values.
Recommendations For Linux kernel version 3.x, consider restricting access to the goodix tool.c file in the Goodix gt915 touchscreen driver to minimize the risk of exploitation. As a temporary workaround, avoid using crafted user-space length values for kernel-memory copies of procfs file content until a patch is available.

Exploit

Correção

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-4740

Produtos afetados

Linux Kernel