PT-2013-6342 · Suse+2 · Kernel-Pae-Devel+7

Publicado

1970-01-01

·

Atualizado

2017-08-29

·

CVE-2014-1444

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SUSE Linux Enterprise kernel-ec2-devel (affected versions not specified) SUSE Linux Enterprise kernel-pae-devel (affected versions not specified) SUSE Linux Enterprise kernel-xen-devel (affected versions not specified) Linux kernel versions prior to 3.11.7 SUSE Linux Enterprise gfs2-kmp-xen (affected versions not specified)
Description The issue concerns multiple vulnerabilities in various packages of the SUSE Linux Enterprise operating system, including kernel-ec2-devel, kernel-pae-devel, kernel-xen-devel, and gfs2-kmp-xen. These vulnerabilities can be exploited remotely and may lead to a breach of confidentiality, integrity, and availability of protected information. A specific vulnerability in the Linux kernel before version 3.11.7 involves the fst get iface function in drivers/net/wan/farsync.c, which does not properly initialize a certain data structure. This allows local users with the CAP NET ADMIN capability to obtain sensitive information from kernel memory by leveraging an SIOCWANDEV ioctl call.
Recommendations For SUSE Linux Enterprise kernel-ec2-devel, consider disabling vulnerable functions until a patch is available. For SUSE Linux Enterprise kernel-pae-devel, restrict access to vulnerable modules to minimize the risk of exploitation. For SUSE Linux Enterprise kernel-xen-devel, avoid using vulnerable parameters in affected API endpoints until the issue is resolved. For Linux kernel versions prior to 3.11.7, update to version 3.11.7 or later to resolve the issue. For SUSE Linux Enterprise gfs2-kmp-xen, consider disabling the vulnerable gfs2-kmp-xen module until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability in some of the affected packages.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2013-1053
ALT-PU-2014-1422
BDU:2015-04307
BDU:2015-04308
BDU:2015-04309
BDU:2015-04310
CVE-2014-1444
DSA-2906-1
OPENSUSE-SU-2014_0677-1
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0652-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2040-1
USN-2042-1
USN-2049-1
USN-2050-1
USN-2066-1
USN-2067-1
USN-2069-1
USN-2128-1
USN-2129-1

Produtos afetados

Alt Linux
Linux Kernel
Suse Linux Enterprise
Suse
Gfs2-Kmp-Xen
Kernel-Ec2-Devel
Kernel-Pae-Devel
Kernel-Xen-Devel