Lucene search

K
cve[email protected]CVE-2013-1929
HistoryJun 07, 2013 - 2:03 p.m.

CVE-2013-1929

2013-06-0714:03:18
CWE-119
web.nvd.nist.gov
64
cve-2013-1929
buffer overflow
tg3_read_vpd
linux kernel
denial of service
execute arbitrary code
nvd

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

6.7 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.8%

Heap-based buffer overflow in the tg3_read_vpd function in drivers/net/ethernet/broadcom/tg3.c in the Linux kernel before 3.8.6 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via crafted firmware that specifies a long string in the Vital Product Data (VPD) data structure.

Affected configurations

NVD
Node
linuxlinux_kernelRange3.8.5
OR
linuxlinux_kernelMatch3.8.0
OR
linuxlinux_kernelMatch3.8.1
OR
linuxlinux_kernelMatch3.8.2
OR
linuxlinux_kernelMatch3.8.3
OR
linuxlinux_kernelMatch3.8.4

References

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

6.7 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.8%