CVE-2013-2852
Linux Kernel 3.3.5 - 'b43' Wireless Driver Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including format string specifiers in an fwpostfix modprobe parameter, leading to improper construction of an error message.
Vulnerabilidad de formato de cadena en la función b43_request_firmware de drivers/net/wireless/b43/main.c en el driver del Broadcom B43 inhalambrico para el kernel Linux hasta la versión v3.9.4 permite a usuarios locales conseguir privilegios haciendo uso de acceso root e incluyendo especificaciones de formato de cadena en un parámetro fwpostfix modprobe, provocando una construcción inapropiada de un mensaje de error
Multiple vulnerabilities has been found and corrected in the Linux kernel. net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an auth_reply message that triggers an attempted build_request operation. The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 3.9.4 do not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory via a crafted IDAGETPCIINFO command for a /dev/ida device, related to the ida_locked_ioctl function in drivers/block/cpqarray.c or a crafted CCISS_PASSTHRU32 command for a /dev/cciss device, related to the cciss_ioctl32_passthru function in drivers/block/cciss.c. Various other issues have also been addressed. The updated packages provides a solution for these security issues.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-04-11 CVE Reserved
- 2013-06-07 CVE Published
- 2013-06-07 First Exploit
- 2024-08-06 CVE Updated
- 2025-06-05 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-134: Use of Externally-Controlled Format String
CAPEC
References (20)
URL | Tag | Source |
---|---|---|
http://git.kernel.org/cgit/linux/kernel/git/linville/wireless.git/commit/?id=9538cbaab6e8b8046039b4b2eb6c9d614dc782bd | X_refsource_confirm | |
http://www.openwall.com/lists/oss-security/2013/06/06/13 | Mailing List |
|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/38559 | 2013-06-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.html | 2023-11-07 | |
http://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2013-1051.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2013-1450.html | 2023-11-07 | |
http://www.debian.org/security/2013/dsa-2766 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1899-1 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1900-1 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1914-1 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1915-1 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1916-1 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1917-1 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1918-1 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1919-1 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1920-1 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1930-1 | 2023-11-07 | |
https://bugzilla.redhat.com/show_bug.cgi?id=969518 | 2013-10-22 | |
https://access.redhat.com/security/cve/CVE-2013-2852 | 2013-10-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 2.6.12 < 3.0.83 Search vendor "Linux" for product "Linux Kernel" and version " >= 2.6.12 < 3.0.83" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 3.1 < 3.2.47 Search vendor "Linux" for product "Linux Kernel" and version " >= 3.1 < 3.2.47" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 3.3 < 3.4.50 Search vendor "Linux" for product "Linux Kernel" and version " >= 3.3 < 3.4.50" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 3.5 < 3.9.7 Search vendor "Linux" for product "Linux Kernel" and version " >= 3.5 < 3.9.7" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 6.0 Search vendor "Debian" for product "Debian Linux" and version "6.0" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 10.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "10.04" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 12.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "12.04" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 12.10 Search vendor "Canonical" for product "Ubuntu Linux" and version "12.10" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 13.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "13.04" | - |
Affected
|