CVE-2013-2596

CVE Details

Release Date:2013-04-09

Description


Integer overflow in the fb_mmap function in drivers/video/fbmem.c inthe Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted /dev/graphics/fb0 mmap2 system calls, as demonstrated by the Motochopper pwn program.

See more information about CVE-2013-2596 from MITRE CVE dictionary and NIST NVD


CVSS v2.0 metrics


NOTE: The following CVSS v2.0 metrics and score provided are preliminary and subject to review.

Base Score: 6 Base Metrics: AV:L/AC:H/Au:S/C:C/I:C/A:C
Access Vector: Local network Attack Complexity: High
Authentication: Requires single instance Confidentiality Impact: Complete
Integrity Impact: Complete Availability Impact: Complete

Errata information


PlatformErrataRelease Date
Oracle Linux version 5 (kernel)ELSA-2016-04502016-03-15
Oracle Linux version 5 (kernel)ELSA-2016-0450-12016-03-16
Oracle Linux version 5 (kernel-uek)ELSA-2014-30822014-10-17
Oracle Linux version 5 (kernel-uek)ELSA-2014-30832014-10-17
Oracle Linux version 5 (mlnx_en-2.6.32-400.36.9.el5uek)ELSA-2014-30832014-10-17
Oracle Linux version 5 (ocfs2-2.6.18-409.0.0.0.1.el5)ELSA-2016-0450-12016-03-16
Oracle Linux version 5 (ocfs2-2.6.18-409.el5)ELSA-2016-04502016-03-15
Oracle Linux version 5 (ofa-2.6.32-400.36.9.el5uek)ELSA-2014-30832014-10-17
Oracle Linux version 5 (oracleasm-2.6.18-409.0.0.0.1.el5)ELSA-2016-0450-12016-03-16
Oracle Linux version 5 (oracleasm-2.6.18-409.el5)ELSA-2016-04502016-03-15
Oracle Linux version 6 (kernel)ELSA-2014-13922014-10-20
Oracle Linux version 6 (kernel-uek)ELSA-2014-30822014-10-17
Oracle Linux version 6 (kernel-uek)ELSA-2014-30832014-10-17
Oracle Linux version 6 (mlnx_en-2.6.32-400.36.9.el6uek)ELSA-2014-30832014-10-17
Oracle Linux version 6 (ofa-2.6.32-400.36.9.el6uek)ELSA-2014-30832014-10-17



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete