PT-2013-3612 · Linux+3 · Linux Kernel+3

Prasad Pandit

·

Published

2013-07-04

·

Updated

2023-02-13

·

CVE-2013-2237

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.9
Description The issue concerns the key notify policy flush function in the Linux kernel, which fails to initialize a certain structure member. This allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify policy interface of an IPSec key socket.
Recommendations For Linux kernel versions prior to 3.9, update to version 3.9 or later to resolve the issue.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2013_1173
CVE-2013-2237
DSA-2745-1
DSA-2766-1
MGASA-2013-0203
MGASA-2013-0204
MGASA-2013-0209
MGASA-2013-0211
MGASA-2013-0212
MGASA-2013-0213
MGASA-2013-0215
RHSA-2013:1166
RHSA-2013:1173
RHSA-2013:1195
RHSA-2013:1264
RHSA-2013_1166
RHSA-2013_1173
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0652-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-1912-1
USN-1913-1
USN-1970-1
USN-1972-1
USN-1973-1
USN-1992-1
USN-1993-1
USN-1995-1
USN-1998-1

Affected Products

Centos
Linux Kernel
Red Hat
Suse