Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2013-2634

Overview

Vulnerability Score 1.9 1.9
CVE Id CVE-2013-2634
Last Modified 06 Feb 2014 11:47:16
Published 22 Mar 2013 07:59:11
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector LOCAL
Access Complexity MEDIUM
Authentication NONE

CVE-2013-2634

Summary

net/dcb/dcbnl.c in the Linux kernel before 3.8.4 does not initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.

Vulnerable Systems

Operating System

  • Linux Kernel 3.8.0

  • Linux Kernel 3.8.1

  • Linux Kernel 3.8.2

  • Linux Kernel 3.8.3


References

CONFIRM - https://github.com/torvalds/linux/commit/29cd8ae0e1a39e239a3a7b67da1986add1199fc0

CONFIRM - http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=29cd8ae0e1a39e239a3a7b67da1986add1199fc0

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=923652

MLIST - [oss-security] 20130320 Re: Linux kernel: net - three info leaks in rtnl

CONFIRM - http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.4

UBUNTU - USN-1829-1

UBUNTU - USN-1814-1

UBUNTU - USN-1813-1

UBUNTU - USN-1812-1

UBUNTU - USN-1811-1

UBUNTU - USN-1809-1

MANDRIVA - MDVSA-2013:176

SUSE - openSUSE-SU-2013:1187

SUSE - openSUSE-SU-2013:1971

REDHAT - RHSA-2013:1051


Last Updated: 27 May 2016 11:02:08