PT-2013-4928 · Linux+1 · Linux Kernel+1

Miroslav Vadkerti

·

Published

2013-11-08

·

Updated

2023-02-13

·

CVE-2013-4270

CVSS v2.0

3.6

Low

VectorAV:L/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.11.5
Description The issue allows local users to bypass intended /proc/sys/net restrictions. This is due to the net ctl permissions function in net/sysctl net.c not properly determining uid and gid values, enabling users to create a crafted application for exploitation.
Recommendations For Linux kernel versions prior to 3.11.5, update to version 3.11.5 or later to resolve the issue.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1422
CVE-2013-4270
RHSA-2014:0100
USN-2020-1
USN-2023-1
USN-2049-1

Affected Products

Alt Linux
Linux Kernel