PT-2013-1106 · Linux+4 · Linux Kernel+4

Mathias Krause

·

Published

2013-02-18

·

Updated

2017-11-29

·

CVE-2013-3225

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.9-rc7 Debian GNU/Linux (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the Linux operating system package, specifically in the Debian GNU/Linux and the Linux kernel. These vulnerabilities can be exploited by a local attacker to compromise the confidentiality, integrity, and availability of protected information. The vulnerability in the Linux kernel, particularly in the rfcomm sock recvmsg function, allows local users to obtain sensitive information from the kernel stack memory. This is achieved through a crafted recvmsg or recvfrom system call, due to the incorrect initialization of a certain length variable.
Recommendations For Linux kernel versions prior to 3.9-rc7, update to version 3.9-rc7 or later to resolve the issue. For Debian GNU/Linux, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03064
CESA-2013_1051
CVE-2013-3225
DSA-2668-1
DSA-2669-1
RHSA-2013:0829
RHSA-2013:1051
RHSA-2013:1080
RHSA-2013_1051
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0652-1
SUSE-SU-2015:1174-1
USN-1837-1
USN-1849-1
USN-1876-1
USN-1877-1
USN-1878-1
USN-1879-1
USN-1880-1
USN-1881-1
USN-1882-1
USN-1883-1

Affected Products

Centos
Debian
Linux Kernel
Red Hat
Suse