PT-2013-1100 · Debian+2 · Debian+2
Andy Lutomirski
·
Published
2013-02-18
·
Updated
2023-02-13
·
CVE-2013-1979
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Debian GNU/Linux versions prior to 3.8.11
Linux kernel versions prior to 3.8.11
Description
The issue concerns multiple vulnerabilities in the Linux package of the Debian GNU/Linux operating system, which can be exploited by a local attacker to compromise the confidentiality, integrity, and availability of protected information. A specific problem is identified in the
scm set cred function, where incorrect uid and gid values are used during credentials passing, allowing local users to gain privileges via a crafted application.Recommendations
For Debian GNU/Linux versions prior to 3.8.11, update to version 3.8.11 or later to resolve the issue.
For Linux kernel versions prior to 3.8.11, update to version 3.8.11 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
scm set cred function until a patch is available.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Linux Kernel
Suse