Lucene search

K
cve[email protected]CVE-2013-3301
HistoryApr 29, 2013 - 2:55 p.m.

CVE-2013-3301

2013-04-2914:55:04
web.nvd.nist.gov
69
linux kernel
ftrace
denial of service
cve-2013-3301
security vulnerability
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

5.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.7%

The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then making an lseek system call.

Affected configurations

NVD
Node
linuxlinux_kernelRange3.13.2.44
OR
linuxlinux_kernelRange3.33.4.49
OR
linuxlinux_kernelRange3.53.8.8
Node
redhatenterprise_linuxMatch6.0
OR
redhatenterprise_mrgMatch2.0
Node
suselinux_enterprise_desktopMatch11sp3
OR
suselinux_enterprise_high_availability_extensionMatch11sp3
OR
suselinux_enterprise_serverMatch11sp3-
OR
suselinux_enterprise_serverMatch11sp3vmware

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

5.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.7%