PT-2013-3412 · Linux+4 · Linux Kernel+4

·

CVE-2013-1827

·

Published

2013-03-07

·

Updated

2023-02-13

CVSS v2.0

6.2

Medium

VectorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.5.4
Description The issue allows local users to gain privileges or cause a denial of service, resulting in a NULL pointer dereference and system crash. This can be achieved by leveraging the CAP NET ADMIN capability for a certain sender or receiver getsockopt call, specifically affecting the net/dccp/ccid.h file in the Linux kernel.
Recommendations For Linux kernel versions prior to 3.5.4, update to version 3.5.4 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2013-1178
CESA-2013_0744
CVE-2013-1827
RHSA-2013:0744
RHSA-2013_0744
SUSE-SU-2015:0652-1
USN-1594-1
USN-1599-1
USN-1607-1
USN-1609-1
USN-1610-1
USN-1651-1
USN-1653-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse