CVE-2013-1772 - CERT CVE
ID CVE-2013-1772
Sažetak The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33 does not properly remove a prefix string from a syslog header, which allows local users to cause a denial of service (buffer overflow and system crash) by leveraging /dev/kmsg write access and triggering a call_console_drivers function call.
Reference
CVSS
Base: 4.0
Impact: 6.9
Exploitability:1.9
Pristup
VektorSloženostAutentikacija
LOCAL HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE NONE COMPLETE
CVSS vektor AV:L/AC:H/Au:N/C:N/I:N/A:C
Zadnje važnije ažuriranje 22-08-2013 - 06:51
Objavljeno 28-02-2013 - 19:55