Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2013-1827

Overview

Vulnerability Score 6.2 6.2
CVE Id CVE-2013-1827
Last Modified 04 Jun 2013 11:42:37
Published 22 Mar 2013 07:59:11
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector LOCAL
Access Complexity HIGH
Authentication NONE

CVE-2013-1827

Summary

net/dccp/ccid.h in the Linux kernel before 3.5.4 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability for a certain (1) sender or (2) receiver getsockopt call.

Vulnerable Systems

Operating System

  • Linux Kernel 3.5.1

  • Linux Kernel 3.5.2

  • Linux Kernel 3.5.3


References

CONFIRM - https://github.com/torvalds/linux/commit/276bdb82dedb290511467a5a4fdbe9f0b52dce6f

CONFIRM - http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=276bdb82dedb290511467a5a4fdbe9f0b52dce6f

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=919164

MLIST - [oss-security] 20130307 Re: CVE Requests (maybe): Linux kernel: various info leaks, some NULL ptr derefs

CONFIRM - http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.5.4

REDHAT - RHSA-2013:0744


Last Updated: 27 May 2016 11:02:07