Lucene search

K
ubuntuUbuntuUSN-1749-1
HistoryFeb 26, 2013 - 12:00 a.m.

Linux kernel (Quantal HWE) vulnerability

2013-02-2600:00:00
ubuntu.com
36

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.1

Confidence

Low

EPSS

0.001

Percentile

25.8%

Releases

  • Ubuntu 12.04

Packages

  • linux-lts-quantal - Linux hardware enablement kernel from Quantal

Details

Mathias Krause discovered a bounds checking error for netlink messages
requesting SOCK_DIAG_BY_FAMILY. An unprivileged local user could exploit
this flaw to crash the system or run programs as an administrator.

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.1

Confidence

Low

EPSS

0.001

Percentile

25.8%