Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2013-1772
HistoryFeb 28, 2013 - 7:55 p.m.

CVE-2013-1772

2013-02-2819:55:01
Debian Security Bug Tracker
security-tracker.debian.org
17

CVSS2

4

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:N/I:N/A:C

EPSS

0

Percentile

5.1%

The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33 does not properly remove a prefix string from a syslog header, which allows local users to cause a denial of service (buffer overflow and system crash) by leveraging /dev/kmsg write access and triggering a call_console_drivers function call.

CVSS2

4

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:N/I:N/A:C

EPSS

0

Percentile

5.1%