Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2013-0871

Overview

Vulnerability Score 6.9 6.9
CVE Id CVE-2013-0871
Last Modified 20 Jun 2013 11:16:21
Published 17 Feb 2013 11:41:50
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector LOCAL
Access Complexity MEDIUM
Authentication NONE

CVE-2013-0871

Summary

Race condition in the ptrace functionality in the Linux kernel before 3.7.5 allows local users to gain privileges via a PTRACE_SETREGS ptrace system call in a crafted application, as demonstrated by ptrace_death.

Vulnerable Systems

Operating System

  • Linux Kernel 3.0

  • Linux Kernel 3.0.1

  • Linux Kernel 3.0.10

  • Linux Kernel 3.0.11

  • Linux Kernel 3.0.12

  • Linux Kernel 3.0.13

  • Linux Kernel 3.0.14

  • Linux Kernel 3.0.15

  • Linux Kernel 3.0.16

  • Linux Kernel 3.0.17

  • Linux Kernel 3.0.18

  • Linux Kernel 3.0.19

  • Linux Kernel 3.0.2

  • Linux Kernel 3.0.20

  • Linux Kernel 3.0.21

  • Linux Kernel 3.0.22

  • Linux Kernel 3.0.23

  • Linux Kernel 3.0.24

  • Linux Kernel 3.0.25

  • Linux Kernel 3.0.26

  • Linux Kernel 3.0.27

  • Linux Kernel 3.0.28

  • Linux Kernel 3.0.29

  • Linux Kernel 3.0.3

  • Linux Kernel 3.0.30

  • Linux Kernel 3.0.31

  • Linux Kernel 3.0.32

  • Linux Kernel 3.0.33

  • Linux Kernel 3.0.34

  • Linux Kernel 3.0.35

  • Linux Kernel 3.0.36

  • Linux Kernel 3.0.37

  • Linux Kernel 3.0.38

  • Linux Kernel 3.0.39

  • Linux Kernel 3.0.4

  • Linux Kernel 3.0.40

  • Linux Kernel 3.0.41

  • Linux Kernel 3.0.42

  • Linux Kernel 3.0.43

  • Linux Kernel 3.0.44

  • Linux Kernel 3.0.5

  • Linux Kernel 3.0.6

  • Linux Kernel 3.0.7

  • Linux Kernel 3.0.8

  • Linux Kernel 3.0.9

  • Linux Kernel 3.1

  • Linux Kernel 3.1.1

  • Linux Kernel 3.1.10

  • Linux Kernel 3.1.2

  • Linux Kernel 3.1.3

  • Linux Kernel 3.1.4

  • Linux Kernel 3.1.5

  • Linux Kernel 3.1.6

  • Linux Kernel 3.1.7

  • Linux Kernel 3.1.8

  • Linux Kernel 3.1.9

  • Linux Kernel 3.2

  • Linux Kernel 3.2.1

  • Linux Kernel 3.2.10

  • Linux Kernel 3.2.11

  • Linux Kernel 3.2.12

  • Linux Kernel 3.2.13

  • Linux Kernel 3.2.14

  • Linux Kernel 3.2.15

  • Linux Kernel 3.2.16

  • Linux Kernel 3.2.17

  • Linux Kernel 3.2.18

  • Linux Kernel 3.2.19

  • Linux Kernel 3.2.2

  • Linux Kernel 3.2.20

  • Linux Kernel 3.2.21

  • Linux Kernel 3.2.22

  • Linux Kernel 3.2.23

  • Linux Kernel 3.2.24

  • Linux Kernel 3.2.25

  • Linux Kernel 3.2.26

  • Linux Kernel 3.2.27

  • Linux Kernel 3.2.28

  • Linux Kernel 3.2.29

  • Linux Kernel 3.2.3

  • Linux Kernel 3.2.30

  • Linux Kernel 3.2.4

  • Linux Kernel 3.2.5

  • Linux Kernel 3.2.6

  • Linux Kernel 3.2.7

  • Linux Kernel 3.2.8

  • Linux Kernel 3.2.9

  • Linux Kernel 3.3

  • Linux Kernel 3.3.1

  • Linux Kernel 3.3.2

  • Linux Kernel 3.3.3

  • Linux Kernel 3.3.4

  • Linux Kernel 3.3.5

  • Linux Kernel 3.3.6

  • Linux Kernel 3.3.7

  • Linux Kernel 3.3.8

  • Linux Kernel 3.4

  • Linux Kernel 3.4.1

  • Linux Kernel 3.4.10

  • Linux Kernel 3.4.11

  • Linux Kernel 3.4.12

  • Linux Kernel 3.4.13

  • Linux Kernel 3.4.14

  • Linux Kernel 3.4.15

  • Linux Kernel 3.4.16

  • Linux Kernel 3.4.17

  • Linux Kernel 3.4.18

  • Linux Kernel 3.4.19

  • Linux Kernel 3.4.2

  • Linux Kernel 3.4.20

  • Linux Kernel 3.4.21

  • Linux Kernel 3.4.22

  • Linux Kernel 3.4.23

  • Linux Kernel 3.4.24

  • Linux Kernel 3.4.3

  • Linux Kernel 3.4.4

  • Linux Kernel 3.4.5

  • Linux Kernel 3.4.6

  • Linux Kernel 3.4.7

  • Linux Kernel 3.4.8

  • Linux Kernel 3.4.9

  • Linux Kernel 3.5.1

  • Linux Kernel 3.5.2

  • Linux Kernel 3.5.3

  • Linux Kernel 3.5.4

  • Linux Kernel 3.5.5

  • Linux Kernel 3.5.6

  • Linux Kernel 3.5.7

  • Linux Kernel 3.6.10

  • Linux Kernel 3.6.11

  • Linux Kernel 3.6.9

  • Linux Kernel 3.7

  • Linux Kernel 3.7.1

  • Linux Kernel 3.7.2

  • Linux Kernel 3.7.3

  • Linux Kernel 3.7.4


References

CONFIRM - https://github.com/torvalds/linux/commit/9899d11f654474d2d54ea52ceaa2a1f4db3abd68

MLIST - [oss-security] 20130215 Linux kernel race condition with PTRACE_SETREGS (CVE-2013-0871)

CONFIRM - http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=9899d11f654474d2d54ea52ceaa2a1f4db3abd68

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=911937

CONFIRM - http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.5

UBUNTU - USN-1745-1

UBUNTU - USN-1744-1

UBUNTU - USN-1743-1

UBUNTU - USN-1742-1

UBUNTU - USN-1741-1

UBUNTU - USN-1740-1

UBUNTU - USN-1739-1

UBUNTU - USN-1738-1

UBUNTU - USN-1737-1

UBUNTU - USN-1736-1

DEBIAN - DSA-2632

REDHAT - RHSA-2013:0567

SUSE - SUSE-SU-2013:0341

REDHAT - RHSA-2013:0695

REDHAT - RHSA-2013:0662

REDHAT - RHSA-2013:0661

SUSE - openSUSE-SU-2013:0925

SUSE - SUSE-SU-2013:0674

Related Patches

Red Hat 2013:0621-01 RHSA Important: kernel security update for RHEL 5 x86

Novell SUSE 2013:8518 kernel security update for SLE 10 SP4 i586

Novell SUSE 2013:8527 kernel security update for SLE 10 SP4 x86_64


Last Updated: 27 May 2016 11:01:59