CVE-2013-2852
Linux Kernel 3.3.5 - 'b43' Wireless Driver Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including format string specifiers in an fwpostfix modprobe parameter, leading to improper construction of an error message.
Vulnerabilidad de formato de cadena en la función b43_request_firmware de drivers/net/wireless/b43/main.c en el driver del Broadcom B43 inhalambrico para el kernel Linux hasta la versión v3.9.4 permite a usuarios locales conseguir privilegios haciendo uso de acceso root e incluyendo especificaciones de formato de cadena en un parámetro fwpostfix modprobe, provocando una construcción inapropiada de un mensaje de error
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-04-11 CVE Reserved
- 2013-06-07 CVE Published
- 2013-06-07 First Exploit
- 2023-11-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-134: Use of Externally-Controlled Format String
CAPEC
References (20)
URL | Tag | Source |
---|---|---|
http://git.kernel.org/cgit/linux/kernel/git/linville/wireless.git/commit/?id=9538cbaab6e8b8046039b4b2eb6c9d614dc782bd | X_refsource_confirm | |
http://www.openwall.com/lists/oss-security/2013/06/06/13 | Mailing List |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/38559 | 2013-06-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.html | 2023-11-07 | |
http://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2013-1051.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2013-1450.html | 2023-11-07 | |
http://www.debian.org/security/2013/dsa-2766 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1899-1 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1900-1 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1914-1 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1915-1 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1916-1 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1917-1 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1918-1 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1919-1 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1920-1 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1930-1 | 2023-11-07 | |
https://bugzilla.redhat.com/show_bug.cgi?id=969518 | 2013-10-22 | |
https://access.redhat.com/security/cve/CVE-2013-2852 | 2013-10-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 2.6.12 < 3.0.83 Search vendor "Linux" for product "Linux Kernel" and version " >= 2.6.12 < 3.0.83" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 3.1 < 3.2.47 Search vendor "Linux" for product "Linux Kernel" and version " >= 3.1 < 3.2.47" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 3.3 < 3.4.50 Search vendor "Linux" for product "Linux Kernel" and version " >= 3.3 < 3.4.50" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 3.5 < 3.9.7 Search vendor "Linux" for product "Linux Kernel" and version " >= 3.5 < 3.9.7" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 6.0 Search vendor "Debian" for product "Debian Linux" and version "6.0" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 10.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "10.04" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 12.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "12.04" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 12.10 Search vendor "Canonical" for product "Ubuntu Linux" and version "12.10" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 13.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "13.04" | - |
Affected
|