PT-2013-6315 · Linux+4 · Linux Kernel+5

Published

1970-01-01

·

Updated

2018-04-28

·

CVE-2013-2929

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SUSE Linux Enterprise kernel-ec2-devel versions prior to 3.12.2 SUSE Linux Enterprise kernel-pae-devel versions prior to 3.12.2 SUSE Linux Enterprise kernel-xen-devel versions prior to 3.12.2 SUSE Linux Enterprise gfs2-kmp-xen versions prior to 3.12.2 Linux kernel versions prior to 3.12.2
Description The issue affects the Linux kernel and can lead to a breach of confidentiality, integrity, and availability of protected information. It is related to the improper use of the get dumpable function, which can allow local users to bypass ptrace restrictions or obtain sensitive information from IA64 scratch registers. The vulnerability can be exploited remotely. The get dumpable() function in the ptrace subsystem is vulnerable to information disclosure. Systems are only vulnerable if the sysctl fs.suid dumpable variable is set to 2, which is not the default value.
Recommendations For SUSE Linux Enterprise kernel-ec2-devel versions prior to 3.12.2, update to version 3.12.2 or later. For SUSE Linux Enterprise kernel-pae-devel versions prior to 3.12.2, update to version 3.12.2 or later. For SUSE Linux Enterprise kernel-xen-devel versions prior to 3.12.2, update to version 3.12.2 or later. For SUSE Linux Enterprise gfs2-kmp-xen versions prior to 3.12.2, update to version 3.12.2 or later. For Linux kernel versions prior to 3.12.2, update to version 3.12.2 or later. As a temporary workaround, consider restricting access to the get dumpable() function until a patch is available.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2013-1221
ALT-PU-2013-1222
ALT-PU-2013-1236
ALT-PU-2014-1189
ALT-PU-2014-1422
BDU:2014-00089
BDU:2015-04307
BDU:2015-04308
BDU:2015-04309
BDU:2015-04310
CESA-2014_0159
CESA-2014_1971
CVE-2013-2929
DSA-2906-1
MGASA-2013-0371
MGASA-2013-0372
MGASA-2013-0373
MGASA-2013-0374
MGASA-2013-0375
RHSA-2014:0100
RHSA-2014:0159
RHSA-2014:0285
RHSA-2014:1971
RHSA-2014_0159
RHSA-2014_0285
RHSA-2014_1971
RHSA-2018:1252
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0652-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2070-1
USN-2075-1
USN-2109-1
USN-2110-1
USN-2111-1
USN-2112-1
USN-2114-1
USN-2115-1
USN-2116-1
USN-2128-1
USN-2129-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse Linux Enterprise
Suse