CVE-2013-2851

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Format string vulnerability in the register_disk function in block/genhd.c in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and writing format string specifiers to /sys/module/md_mod/parameters/new_array in order to create a crafted /dev/md device name.

References

http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.html

http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.html

http://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html

http://marc.info/?l=linux-kernel&m=137055204522556&w=2

http://rhn.redhat.com/errata/RHSA-2013-1645.html

http://rhn.redhat.com/errata/RHSA-2013-1783.html

http://rhn.redhat.com/errata/RHSA-2014-0284.html

http://www.debian.org/security/2013/dsa-2766

http://www.openwall.com/lists/oss-security/2013/06/06/13

http://www.ubuntu.com/usn/USN-1912-1

http://www.ubuntu.com/usn/USN-1913-1

http://www.ubuntu.com/usn/USN-1941-1

http://www.ubuntu.com/usn/USN-1942-1

https://bugzilla.redhat.com/show_bug.cgi?id=969515

Details

Source: MITRE

Published: 2013-06-07

Updated: 2014-03-26

Type: CWE-134

Risk Information

CVSS v2

Base Score: 6

Vector: AV:L/AC:H/Au:S/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 1.5

Severity: MEDIUM

Tenable Plugins

View all (29 total)

IDNameProductFamilySeverity
99163OracleVM 3.3 : Unbreakable / etc (OVMSA-2017-0057) (Dirty COW)NessusOracleVM Local Security Checks
critical
83611SUSE SLES11 Security Update : kernel (SUSE-SU-2014:0287-1)NessusSuSE Local Security Checks
high
79170CentOS 6 : kernel (CESA-2013:1645)NessusCentOS Local Security Checks
medium
79000RHEL 6 : kernel (RHSA-2014:0284)NessusRed Hat Local Security Checks
medium
78983RHEL 6 : kernel (RHSA-2013:1783)NessusRed Hat Local Security Checks
medium
76665RHEL 6 : MRG (RHSA-2013:1264)NessusRed Hat Local Security Checks
high
75184openSUSE Security Update : kernel (openSUSE-SU-2013:1619-1)NessusSuSE Local Security Checks
high
74878openSUSE Security Update : kernel (openSUSE-SU-2013:1971-1)NessusSuSE Local Security Checks
high
71490Scientific Linux Security Update : kernel on SL6.x i386/x86_64 (20131121)NessusScientific Linux Local Security Checks
medium
71108Oracle Linux 6 : Kernel (ELSA-2013-1645)NessusOracle Linux Local Security Checks
medium
71013RHEL 6 : kernel (RHSA-2013:1645)NessusRed Hat Local Security Checks
medium
70200Debian DSA-2766-1 : linux-2.6 - privilege escalation/denial of service/information leakNessusDebian Local Security Checks
medium
70040SuSE 11.3 Security Update : Linux kernel (SAT Patch Numbers 8269 / 8270 / 8283)NessusSuSE Local Security Checks
high
70039SuSE 11.2 Security Update : Linux kernel (SAT Patch Numbers 8263 / 8265 / 8273)NessusSuSE Local Security Checks
high
69942Oracle Linux 5 / 6 : Unbreakable Enterprise Kernel (ELSA-2013-2546)NessusOracle Linux Local Security Checks
high
69809Ubuntu 12.04 LTS : linux vulnerabilities (USN-1941-1)NessusUbuntu Local Security Checks
high
69510Oracle Linux 5 / 6 : Unbreakable Enterprise kernel (ELSA-2013-2543)NessusOracle Linux Local Security Checks
high
69509Oracle Linux 5 / 6 : Unbreakable Enterprise kernel (ELSA-2013-2542)NessusOracle Linux Local Security Checks
medium
69505Debian DSA-2745-1 : linux - privilege escalation/denial of service/information leakNessusDebian Local Security Checks
high
69419Ubuntu 12.04 LTS : linux-lts-raring vulnerabilities (USN-1936-1)NessusUbuntu Local Security Checks
high
69418Ubuntu 13.04 : linux vulnerabilities (USN-1935-1)NessusUbuntu Local Security Checks
high
69417Ubuntu 12.10 : linux vulnerabilities (USN-1932-1)NessusUbuntu Local Security Checks
high
69416Ubuntu 12.04 LTS : linux-lts-quantal vulnerabilities (USN-1931-1)NessusUbuntu Local Security Checks
high
69122Ubuntu 10.04 LTS : linux-ec2 vulnerabilities (USN-1913-1)NessusUbuntu Local Security Checks
medium
69121Ubuntu 10.04 LTS : linux vulnerabilities (USN-1912-1)NessusUbuntu Local Security Checks
medium
67351Fedora 17 : kernel-3.9.8-100.fc17 (2013-9123)NessusFedora Local Security Checks
high
67285Fedora 18 : kernel-3.9.5-201.fc18 (2013-10695)NessusFedora Local Security Checks
high
67284Fedora 19 : kernel-3.9.5-301.fc19 (2013-10689)NessusFedora Local Security Checks
medium
67254Mandriva Linux Security Advisory : kernel (MDVSA-2013:194)NessusMandriva Local Security Checks
high