Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2013-0914

Overview

Vulnerability Score 3.6 3.6
CVE Id CVE-2013-0914
Last Modified 06 Feb 2014 11:45:24
Published 22 Mar 2013 07:59:11
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2013-0914

Summary

The flush_signal_handlers function in kernel/signal.c in the Linux kernel before 3.8.4 preserves the value of the sa_restorer field across an exec operation, which makes it easier for local users to bypass the ASLR protection mechanism via a crafted application containing a sigaction system call.

Vulnerable Systems

Operating System

  • Linux Kernel 3.8.0

  • Linux Kernel 3.8.1

  • Linux Kernel 3.8.2

  • Linux Kernel 3.8.3


References

CONFIRM - https://github.com/torvalds/linux/commit/2ca39528c01a933f6689cd6505ce65bd6d68a530

CONFIRM - http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2ca39528c01a933f6689cd6505ce65bd6d68a530

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=920499

MLIST - [oss-security] 20130311 CVE-2013-0914 Linux kernel sa_restorer information leak

CONFIRM - http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.4

UBUNTU - USN-1788-1

UBUNTU - USN-1787-1

UBUNTU - USN-1798-1

UBUNTU - USN-1797-1

UBUNTU - USN-1796-1

UBUNTU - USN-1795-1

UBUNTU - USN-1794-1

UBUNTU - USN-1793-1

UBUNTU - USN-1792-1

MANDRIVA - MDVSA-2013:176

SUSE - openSUSE-SU-2013:1187

SUSE - openSUSE-SU-2013:1971

REDHAT - RHSA-2013:1051


Last Updated: 27 May 2016 11:04:03