CVE-2013-1860

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Heap-based buffer overflow in the wdm_in_callback function in drivers/usb/class/cdc-wdm.c in the Linux kernel before 3.8.4 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted cdc-wdm USB device.

References

http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=c0f5ecee4e741667b2493c742b60b6218d40b3aa

http://rhn.redhat.com/errata/RHSA-2014-0328.html

http://rhn.redhat.com/errata/RHSA-2014-0339.html

http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.4

http://www.mandriva.com/security/advisories?name=MDVSA-2013:176

http://www.openwall.com/lists/oss-security/2013/03/15/3

http://www.securityfocus.com/bid/58510

http://www.ubuntu.com/usn/USN-1809-1

http://www.ubuntu.com/usn/USN-1811-1

http://www.ubuntu.com/usn/USN-1812-1

http://www.ubuntu.com/usn/USN-1813-1

http://www.ubuntu.com/usn/USN-1814-1

http://www.ubuntu.com/usn/USN-1829-1

https://bugzilla.redhat.com/show_bug.cgi?id=921970

https://github.com/torvalds/linux/commit/c0f5ecee4e741667b2493c742b60b6218d40b3aa

Details

Source: MITRE

Published: 2013-03-22

Updated: 2016-12-08

Type: CWE-119

Risk Information

CVSS v2

Base Score: 6.9

Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.4

Severity: MEDIUM

Tenable Plugins

View all (20 total)

IDNameProductFamilySeverity
83640SUSE SLES11 Security Update : kernel (SUSE-SU-2014:1138-1)NessusSuSE Local Security Checks
medium
79003RHEL 6 : rhev-hypervisor6 (RHSA-2014:0339)NessusRed Hat Local Security Checks
medium
76660RHEL 6 : MRG (RHSA-2013:0829)NessusRed Hat Local Security Checks
high
73200Scientific Linux Security Update : kernel on SL6.x i386/x86_64 (20140325)NessusScientific Linux Local Security Checks
high
73198RHEL 6 : kernel (RHSA-2014:0328)NessusRed Hat Local Security Checks
high
73196Oracle Linux 6 : kernel (ELSA-2014-0328)NessusOracle Linux Local Security Checks
high
73191CentOS 6 : kernel (CESA-2014:0328)NessusCentOS Local Security Checks
high
69942Oracle Linux 5 / 6 : Unbreakable Enterprise Kernel (ELSA-2013-2546)NessusOracle Linux Local Security Checks
high
68856Oracle Linux 5 / 6 : Unbreakable Enterprise kernel Security (ELSA-2013-2534)NessusOracle Linux Local Security Checks
high
68855Oracle Linux 5 / 6 : Unbreakable Enterprise kernel Security (ELSA-2013-2525)NessusOracle Linux Local Security Checks
high
66975Mandriva Linux Security Advisory : kernel (MDVSA-2013:176)NessusMandriva Local Security Checks
high
66494Ubuntu 10.04 LTS : linux-ec2 vulnerabilities (USN-1829-1)NessusUbuntu Local Security Checks
medium
66467Ubuntu 10.04 LTS : linux vulnerabilities (USN-1824-1)NessusUbuntu Local Security Checks
medium
66431Debian DSA-2668-1 : linux-2.6 - privilege escalation/denial of service/information leakNessusDebian Local Security Checks
medium
66344SuSE 11.2 Security Update : Linux kernel (SAT Patch Numbers 7667 / 7669 / 7675)NessusSuSE Local Security Checks
high
66302Ubuntu 12.10 : linux vulnerabilities (USN-1813-1)NessusUbuntu Local Security Checks
high
66292Ubuntu 12.04 LTS : linux-lts-quantal vulnerabilities (USN-1812-1)NessusUbuntu Local Security Checks
high
66291Ubuntu 12.04 LTS : linux vulnerabilities (USN-1809-1)NessusUbuntu Local Security Checks
high
65650Fedora 17 : kernel-3.8.3-103.fc17 (2013-3909)NessusFedora Local Security Checks
high
65622Fedora 18 : kernel-3.8.3-203.fc18 (2013-4012)NessusFedora Local Security Checks
medium