Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-4254
HistoryAug 24, 2013 - 12:00 a.m.

CVE-2013-4254

2013-08-2400:00:00
ubuntu.com
ubuntu.com
7

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

EPSS

0

Percentile

10.1%

The validate_event function in arch/arm/kernel/perf_event.c in the Linux
kernel before 3.10.8 on the ARM platform allows local users to gain
privileges or cause a denial of service (NULL pointer dereference and
system crash) by adding a hardware event to an event group led by a
software event.

Bugs

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

EPSS

0

Percentile

10.1%