Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-1979
HistoryApr 26, 2013 - 12:00 a.m.

CVE-2013-1979

2013-04-2600:00:00
ubuntu.com
ubuntu.com
25

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.001

Percentile

46.5%

The scm_set_cred function in include/net/scm.h in the Linux kernel before
3.8.11 uses incorrect uid and gid values during credentials passing, which
allows local users to gain privileges via a crafted application.

Bugs

Notes

Author Note
seth-arnold 41c21e351e79004dbb4efa4bc14a53a7e0af38c5 is additional hardening; it does not on its own fix this CVE, nor will it get its own CVE number, though it is useful enough to be included in an update. Andy recommended applying in conjunction with 83f1b4ba917db5dc5a061a44b3403ddb6e783494.

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.001

Percentile

46.5%