PT-2013-4011 · Linux+4 · Linux Kernel+4

Kees Cook

·

Published

2013-09-13

·

Updated

2016-12-31

·

CVE-2013-2892

CVSS v2.0

4.7

Medium

VectorAV:L/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.12
Description The issue affects the Human Interface Device (HID) subsystem in the Linux kernel. It allows physically proximate attackers to cause a denial of service via a crafted device. This is due to a heap-based out-of-bounds write in the drivers/hid/hid-pl.c file when CONFIG HID PANTHERLORD is enabled.
Recommendations For Linux kernel versions prior to 3.12, update to version 3.12 or later to resolve the issue.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2013-1178
ALT-PU-2014-1422
CESA-2013_1645
CVE-2013-2892
DSA-2766-1
MGASA-2013-0342
MGASA-2013-0343
MGASA-2013-0344
MGASA-2013-0345
MGASA-2013-0346
MGASA-2013-0371
MGASA-2013-0372
MGASA-2013-0373
MGASA-2013-0374
MGASA-2013-0375
RHSA-2013:1490
RHSA-2013:1527
RHSA-2013:1645
RHSA-2013_1645
SUSE-SU-2015:0652-1
USN-1976-1
USN-1977-1
USN-1995-1
USN-1998-1
USN-2019-1
USN-2021-1
USN-2022-1
USN-2024-1
USN-2038-1
USN-2039-1
USN-2050-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse