CVE-2013-2635

low
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The rtnl_fill_ifinfo function in net/core/rtnetlink.c in the Linux kernel before 3.8.4 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.

References

http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=84d73cd3fb142bf1298a8c13fd4ca50fd2432372

http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00018.html

http://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html

http://rhn.redhat.com/errata/RHSA-2013-1051.html

http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.4

http://www.mandriva.com/security/advisories?name=MDVSA-2013:176

http://www.openwall.com/lists/oss-security/2013/03/20/1

http://www.ubuntu.com/usn/USN-1809-1

http://www.ubuntu.com/usn/USN-1811-1

http://www.ubuntu.com/usn/USN-1812-1

http://www.ubuntu.com/usn/USN-1813-1

http://www.ubuntu.com/usn/USN-1814-1

https://bugzilla.redhat.com/show_bug.cgi?id=923652

https://github.com/torvalds/linux/commit/84d73cd3fb142bf1298a8c13fd4ca50fd2432372

Details

Source: MITRE

Published: 2013-03-22

Updated: 2014-02-07

Type: CWE-399

Risk Information

CVSS v2

Base Score: 1.9

Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 3.4

Severity: LOW

Tenable Plugins

View all (16 total)

IDNameProductFamilySeverity
76660RHEL 6 : MRG (RHSA-2013:0829)NessusRed Hat Local Security Checks
high
74878openSUSE Security Update : kernel (openSUSE-SU-2013:1971-1)NessusSuSE Local Security Checks
high
70222Amazon Linux AMI : kernel (ALAS-2013-218)NessusAmazon Linux Local Security Checks
medium
69942Oracle Linux 5 / 6 : Unbreakable Enterprise Kernel (ELSA-2013-2546)NessusOracle Linux Local Security Checks
high
68978Oracle Linux 5 / 6 : unbreakable enterprise kernel (ELSA-2013-2538)NessusOracle Linux Local Security Checks
high
68945Scientific Linux Security Update : kernel on SL6.x i386/x86_64 (20130716)NessusScientific Linux Local Security Checks
medium
68940CentOS 6 : kernel (CESA-2013:1051)NessusCentOS Local Security Checks
medium
68921RHEL 6 : kernel (RHSA-2013:1051)NessusRed Hat Local Security Checks
medium
68920Oracle Linux 6 : kernel (ELSA-2013-1051)NessusOracle Linux Local Security Checks
medium
66975Mandriva Linux Security Advisory : kernel (MDVSA-2013:176)NessusMandriva Local Security Checks
high
66344SuSE 11.2 Security Update : Linux kernel (SAT Patch Numbers 7667 / 7669 / 7675)NessusSuSE Local Security Checks
high
66302Ubuntu 12.10 : linux vulnerabilities (USN-1813-1)NessusUbuntu Local Security Checks
high
66292Ubuntu 12.04 LTS : linux-lts-quantal vulnerabilities (USN-1812-1)NessusUbuntu Local Security Checks
high
66291Ubuntu 12.04 LTS : linux vulnerabilities (USN-1809-1)NessusUbuntu Local Security Checks
high
65759Fedora 17 : kernel-3.8.4-102.fc17 (2013-4357)NessusFedora Local Security Checks
medium
65664Fedora 18 : kernel-3.8.4-202.fc18 (2013-4240)NessusFedora Local Security Checks
medium