Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-1772

Опубликовано: 22 фев. 2013
Источник: redhat
CVSS2: 3.8
EPSS Низкий

Описание

The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33 does not properly remove a prefix string from a syslog header, which allows local users to cause a denial of service (buffer overflow and system crash) by leveraging /dev/kmsg write access and triggering a call_console_drivers function call.

Отчет

This issue did not affect the versions of kernel package as shipped with Red Hat Enterprise Linux 5 and 6. Future kernel updates for Red Hat Enterprise MRG 2 may address this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise MRG 2kernel-rtFixedRHSA-2013:056606.03.2013

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=916075kernel: call_console_drivers() function log prefix stripping DoS

EPSS

Процентиль: 13%
0.00045
Низкий

3.8 Low

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33 does not properly remove a prefix string from a syslog header, which allows local users to cause a denial of service (buffer overflow and system crash) by leveraging /dev/kmsg write access and triggering a call_console_drivers function call.

nvd
больше 12 лет назад

The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33 does not properly remove a prefix string from a syslog header, which allows local users to cause a denial of service (buffer overflow and system crash) by leveraging /dev/kmsg write access and triggering a call_console_drivers function call.

debian
больше 12 лет назад

The log_prefix function in kernel/printk.c in the Linux kernel 3.x bef ...

github
около 3 лет назад

The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33 does not properly remove a prefix string from a syslog header, which allows local users to cause a denial of service (buffer overflow and system crash) by leveraging /dev/kmsg write access and triggering a call_console_drivers function call.

oracle-oval
почти 12 лет назад

ELSA-2013-2546: Unbreakable Enterprise Kernel security and bug fix update (IMPORTANT)

EPSS

Процентиль: 13%
0.00045
Низкий

3.8 Low

CVSS2