PT-2013-1099 · Linux+3 · Linux Kernel+3

Brad Spengler

+2

·

Published

2013-02-18

·

Updated

2023-02-13

·

CVE-2013-1929

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.8.6
Description The issue concerns multiple vulnerabilities in the Linux operating system, specifically in the Debian GNU/Linux package, which can be exploited by a local attacker to compromise the confidentiality, integrity, and availability of protected information. A heap-based buffer overflow vulnerability exists in the tg3 read vpd function in the Linux kernel, allowing physically proximate attackers to cause a denial of service or possibly execute arbitrary code via crafted firmware.
Recommendations For Linux kernel versions prior to 3.8.6, update to version 3.8.6 or later to resolve the issue. As a temporary workaround, consider restricting physical access to the system to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03064
CESA-2013_1645
CVE-2013-1929
DSA-2668-1
DSA-2669-1
RHSA-2013:0829
RHSA-2013:1034
RHSA-2013:1645
RHSA-2013_1034
RHSA-2013_1645
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-1833-1
USN-1834-1
USN-1835-1
USN-1836-1
USN-1838-1
USN-1839-1

Affected Products

Centos
Linux Kernel
Red Hat
Suse