PT-2013-5169 · Linux · Linux Kernel
Jonathan Salwan
·
Publicado
2013-11-12
·
Atualizado
2013-11-14
·
CVE-2013-4740
CVSS v2.0
6.9
Média
| Vetor | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 3.x
Description
The issue relies on user-space length values for kernel-memory copies of procfs file content, allowing attackers to gain privileges or cause a denial of service (memory corruption) via an application that provides crafted values.
Recommendations
For Linux kernel version 3.x, consider restricting access to the
goodix tool.c file in the Goodix gt915 touchscreen driver to minimize the risk of exploitation. As a temporary workaround, avoid using crafted user-space length values for kernel-memory copies of procfs file content until a patch is available.Exploit
Correção
Race Condition
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Linux Kernel