PT-2013-1106 · Linux+4 · Linux Kernel+4
Mathias Krause
·
Published
2013-02-18
·
Updated
2017-11-29
·
CVE-2013-3225
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 3.9-rc7
Debian GNU/Linux (affected versions not specified)
Description
The issue concerns multiple vulnerabilities in the Linux operating system package, specifically in the Debian GNU/Linux and the Linux kernel. These vulnerabilities can be exploited by a local attacker to compromise the confidentiality, integrity, and availability of protected information. The vulnerability in the Linux kernel, particularly in the
rfcomm sock recvmsg function, allows local users to obtain sensitive information from the kernel stack memory. This is achieved through a crafted recvmsg or recvfrom system call, due to the incorrect initialization of a certain length variable.Recommendations
For Linux kernel versions prior to 3.9-rc7, update to version 3.9-rc7 or later to resolve the issue.
For Debian GNU/Linux, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Debian
Linux Kernel
Red Hat
Suse