Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2013-2635

Overview

Vulnerability Score 1.9 1.9
CVE Id CVE-2013-2635
Last Modified 06 Feb 2014 11:47:16
Published 22 Mar 2013 07:59:11
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector LOCAL
Access Complexity MEDIUM
Authentication NONE

CVE-2013-2635

Summary

The rtnl_fill_ifinfo function in net/core/rtnetlink.c in the Linux kernel before 3.8.4 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.

Vulnerable Systems

Operating System

  • Linux Kernel 3.8.0

  • Linux Kernel 3.8.1

  • Linux Kernel 3.8.2

  • Linux Kernel 3.8.3


References

CONFIRM - https://github.com/torvalds/linux/commit/84d73cd3fb142bf1298a8c13fd4ca50fd2432372

CONFIRM - http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=84d73cd3fb142bf1298a8c13fd4ca50fd2432372

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=923652

MLIST - [oss-security] 20130320 Re: Linux kernel: net - three info leaks in rtnl

CONFIRM - http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.4

UBUNTU - USN-1814-1

UBUNTU - USN-1813-1

UBUNTU - USN-1812-1

UBUNTU - USN-1811-1

UBUNTU - USN-1809-1

MANDRIVA - MDVSA-2013:176

SUSE - openSUSE-SU-2013:1187

SUSE - openSUSE-SU-2013:1971

REDHAT - RHSA-2013:1051


Last Updated: 27 May 2016 11:02:08