Lucene search

K
cveRedhatCVE-2013-2094
HistoryMay 14, 2013 - 8:55 p.m.

CVE-2013-2094

2013-05-1420:55:01
CWE-189
redhat
web.nvd.nist.gov
747
In Wild
2
linux kernel
privilege escalation
perf_swevent_init
cve-2013-2094
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

High

EPSS

0.002

Percentile

55.2%

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.

Affected configurations

Nvd
Node
linuxlinux_kernelRange<3.0.75
OR
linuxlinux_kernelRange3.13.2.45
OR
linuxlinux_kernelRange3.33.4.42
OR
linuxlinux_kernelRange3.53.8.9
VendorProductVersionCPE
linuxlinux_kernel*cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

References

Social References

More

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

High

EPSS

0.002

Percentile

55.2%