Lucene search

K
cveMitreCVE-2013-2596
HistoryApr 13, 2013 - 2:59 a.m.

CVE-2013-2596

2013-04-1302:59:46
CWE-190
mitre
web.nvd.nist.gov
574
In Wild
2
cve-2013-2596
integer overflow
fb_mmap function
linux kernel
local users
privileges
nvd
security vulnerability

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

40.2%

Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted /dev/graphics/fb0 mmap2 system calls, as demonstrated by the Motochopper pwn program.

Affected configurations

Nvd
Node
linuxlinux_kernelRange2.6.123.0.75
OR
linuxlinux_kernelRange3.13.2.45
OR
linuxlinux_kernelRange3.33.4.42
OR
linuxlinux_kernelRange3.53.8.9
OR
motorolaandroidMatch4.1.2
AND
motorolaatrix_hdMatch-
OR
motorolarazr_hdMatch-
OR
motorolarazr_mMatch-
OR
qualcommmsm8960Match-
VendorProductVersionCPE
linuxlinux_kernel*cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
motorolaandroid4.1.2cpe:2.3:o:motorola:android:4.1.2:*:*:*:*:*:*:*
motorolaatrix_hd-cpe:2.3:h:motorola:atrix_hd:-:*:*:*:*:*:*:*
motorolarazr_hd-cpe:2.3:h:motorola:razr_hd:-:*:*:*:*:*:*:*
motorolarazr_m-cpe:2.3:h:motorola:razr_m:-:*:*:*:*:*:*:*
qualcommmsm8960-cpe:2.3:h:qualcomm:msm8960:-:*:*:*:*:*:*:*

References

Social References

More

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

40.2%