PT-2013-3973 · Linux+3 · Linux Kernel+3
Kees Cook
·
Published
2013-06-07
·
Updated
2023-08-11
·
CVE-2013-2852
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions through 3.9.4
Description
The issue allows local users to gain privileges by leveraging root access and including format string specifiers in an
fwpostfix modprobe parameter, leading to improper construction of an error message in the b43 request firmware function. This is located in the Broadcom B43 wireless driver.Recommendations
For Linux kernel versions through 3.9.4, consider restricting access to the
b43 request firmware function until a patch is available. As a temporary workaround, avoid using the fwpostfix modprobe parameter with format string specifiers to minimize the risk of exploitation.Exploit
Fix
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Linux Kernel
Red Hat
Suse