PT-2013-2222 · Linux+3 · Linux Kernel+3

·

CVE-2013-0310

·

Published

2013-02-20

·

Updated

2023-02-13

CVSS v2.0

6.6

Medium

VectorAV:L/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.4.8
Description The issue allows local users to cause a denial of service, resulting in a system crash due to a NULL pointer dereference. This is achieved through an IPOPT CIPSO IP OPTIONS setsockopt system call. The cipso v4 validate function in net/ipv4/cipso ipv4.c is the vulnerable component.
Recommendations For Linux kernel versions prior to 3.4.8, update to version 3.4.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the setsockopt system call to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2013_0496
CVE-2013-0310
RHSA-2013:0496
RHSA-2013_0496
SUSE-SU-2015:0652-1
USN-1554-1
USN-1558-1
USN-1563-1
USN-1579-1
USN-1580-1
USN-1651-1
USN-1653-1

Affected Products

Centos
Linux Kernel
Red Hat
Suse