CVE-2013-0871
published 2013-02-18CVE-2013-0871: Race condition in the ptrace functionality in the Linux kernel before 3.7.5 allows local users to gain privileges via a PTRACE_SETREGS ptrace system call in a…
PriorityP427medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
1.43%
70.5th percentile
Race condition in the ptrace functionality in the Linux kernel before 3.7.5 allows local users to gain privileges via a PTRACE_SETREGS ptrace system call in a crafted application, as demonstrated by ptrace_death.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.39-1 (bookworm) | linux 3.2.39-1 (bookworm) |
| linux | linux_kernel | >= 0 < 3.2.39-1 | 3.2.39-1 |
| linux | linux_kernel | >= 0 < 3.2.39-1 | 3.2.39-1 |
| linux | linux_kernel | >= 0 < 3.2.39-1 | 3.2.39-1 |
| linux | linux_kernel | >= 0 < 3.2.39-1 | 3.2.39-1 |
| linux | linux_kernel | >= 3.5 < 3.7.5 | 3.7.5 |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qhf8-3c9f-cgwj: Race condition in the ptrace functionality in the Linux kernel before 3
ghsa_unreviewed·2022-05-17
CVE-2013-0871 [MEDIUM] CWE-362 GHSA-qhf8-3c9f-cgwj: Race condition in the ptrace functionality in the Linux kernel before 3
Race condition in the ptrace functionality in the Linux kernel before 3.7.5 allows local users to gain privileges via a PTRACE_SETREGS ptrace system call in a crafted application, as demonstrated by ptrace_death.
OSV
CVE-2013-0871: Race condition in the ptrace functionality in the Linux kernel before 3
osv·2013-02-18·CVSS 6.9
CVE-2013-0871 [MEDIUM] CVE-2013-0871: Race condition in the ptrace functionality in the Linux kernel before 3
Race condition in the ptrace functionality in the Linux kernel before 3.7.5 allows local users to gain privileges via a PTRACE_SETREGS ptrace system call in a crafted application, as demonstrated by ptrace_death.
VMware
VMware vCenter Chargeback Manager Remote Code Execution
vendor_vmware·2013-06-11·CVSS 5.0
CVE-2013-0166 [MEDIUM] VMware vCenter Chargeback Manager Remote Code Execution
VMSA-2013-0008: VMware vCenter Chargeback Manager Remote Code Execution
a. vCenter Chargeback Manager Remote Code Execution The vCenter Chargeback Manager (CBM) contains a flaw in its handling of file uploads. Exploitation of this issue may allow an unauthenticated attacker to execute code remotely. VMware would like to thank Andrea Micalizzi, aka rgod, for reporting this issue to us through HP's Zero Day Initiative (ZDI). The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2013-3520 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Replace with / Apply Patch VMware Product CBM Product Version 2.01 Running on an
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2013-02-22
CVE-2013-0871 Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to run programs as an administrator.
Suleiman Souhlal, Salman Qazi, Aaron Durbin and Michael Davidson discovered
a race condition in the Linux kernel's ptrace syscall. An unprivileged
local attacker could exploit this flaw to run programs as an administrator.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
Ubuntu
Linux kernel (Oneiric backport) vulnerability
vendor_ubuntu·2013-02-22
CVE-2013-0871 Linux kernel (Oneiric backport) vulnerability
Title: Linux kernel (Oneiric backport) vulnerability
Summary: The system could be made to run programs as an administrator.
Suleiman Souhlal, Salman Qazi, Aaron Durbin and Michael Davidson discovered
a race condition in the Linux kernel's ptrace syscall. An unprivileged
local attacker could exploit this flaw to run programs as an administrator.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2013-02-22·CVSS 6.9
CVE-2013-0871 [MEDIUM] Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to run programs as an administrator.
Suleiman Souhlal, Salman Qazi, Aaron Durbin and Michael Davidson discovered
a race condition in the Linux kernel's ptrace syscall. An unprivileged
local attacker could exploit this flaw to run programs as an administrator.
(CVE-2013-0871)
A flaw was discovered in the Edgeort USB serial converter driver when the
device is disconnected while it is in use. A local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2013-1774)
A flaw was discovered in the ChipIdea Highspeed Dual Role and ChipIdea host
controller drivers in the Linux kernel. A local user could use this flaw to
cause a denial of service (system crash). (CVE-2013-2058)
Instructions: Afte
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2013-02-22·CVSS 6.9
CVE-2013-0871 [MEDIUM] Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to run programs as an administrator.
Suleiman Souhlal, Salman Qazi, Aaron Durbin and Michael Davidson discovered
a race condition in the Linux kernel's ptrace syscall. An unprivileged
local attacker could exploit this flaw to run programs as an administrator.
(CVE-2013-0871)
A flaw was discovered in the Edgeort USB serial converter driver when the
device is disconnected while it is in use. A local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2013-1774)
A flaw was discovered in the ChipIdea Highspeed Dual Role and ChipIdea host
controller drivers in the Linux kernel. A local user could use this flaw to
cause a denial of service (system crash). (CVE-2013-2058)
Instructions: After a stan
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2013-02-22
CVE-2013-0871 Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to run programs as an administrator.
Suleiman Souhlal, Salman Qazi, Aaron Durbin and Michael Davidson discovered
a race condition in the Linux kernel's ptrace syscall. An unprivileged
local attacker could exploit this flaw to run programs as an administrator.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2013-02-22
CVE-2013-0871 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to run programs as an administrator.
Suleiman Souhlal, Salman Qazi, Aaron Durbin and Michael Davidson discovered
a race condition in the Linux kernel's ptrace syscall. An unprivileged
local attacker could exploit this flaw to run programs as an administrator.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Linux kernel (EC2) vulnerability
vendor_ubuntu·2013-02-22
CVE-2013-0871 Linux kernel (EC2) vulnerability
Title: Linux kernel (EC2) vulnerability
Summary: The system could be made to run programs as an administrator.
Suleiman Souhlal, Salman Qazi, Aaron Durbin and Michael Davidson discovered
a race condition in the Linux kernel's ptrace syscall. An unprivileged
local attacker could exploit this flaw to run programs as an administrator.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Linux kernel (Quantal HWE) vulnerability
vendor_ubuntu·2013-02-22·CVSS 6.9
CVE-2013-0871 [MEDIUM] Linux kernel (Quantal HWE) vulnerability
Title: Linux kernel (Quantal HWE) vulnerability
Summary: The system could be made to run programs as an administrator.
Suleiman Souhlal, Salman Qazi, Aaron Durbin and Michael Davidson discovered
a race condition in the Linux kernel's ptrace syscall. An unprivileged
local attacker could exploit this flaw to run programs as an administrator.
(CVE-2013-0871)
A flaw was discovered in the Edgeort USB serial converter driver when the
device is disconnected while it is in use. A local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2013-1774)
A flaw was discovered in the ChipIdea Highspeed Dual Role and ChipIdea host
controller drivers in the Linux kernel. A local user could use this flaw to
cause a denial of service (system crash). (CVE-2013-2058)
Instructions
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2013-02-22
CVE-2013-0871 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to run programs as an administrator.
Suleiman Souhlal, Salman Qazi, Aaron Durbin and Michael Davidson discovered
a race condition in the Linux kernel's ptrace syscall. An unprivileged
local attacker could exploit this flaw to run programs as an administrator.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually
Red Hat
kernel: race condition with PTRACE_SETREGS
vendor_redhat·2013-02-15·CVSS 6.9
CVE-2013-0871 [MEDIUM] kernel: race condition with PTRACE_SETREGS
kernel: race condition with PTRACE_SETREGS
Race condition in the ptrace functionality in the Linux kernel before 3.7.5 allows local users to gain privileges via a PTRACE_SETREGS ptrace system call in a crafted application, as demonstrated by ptrace_death.
Statement: This issue did affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2. Future updates may address this issue.
Please note that while a public non-weaponized exploit exists, according to our testing the issue is very hard to hit.
Debian
CVE-2013-0871: linux - Race condition in the ptrace functionality in the Linux kernel before 3.7.5 allo...
vendor_debian·2013·CVSS 6.9
CVE-2013-0871 [MEDIUM] CVE-2013-0871: linux - Race condition in the ptrace functionality in the Linux kernel before 3.7.5 allo...
Race condition in the ptrace functionality in the Linux kernel before 3.7.5 allows local users to gain privileges via a PTRACE_SETREGS ptrace system call in a crafted application, as demonstrated by ptrace_death.
Scope: local
bookworm: resolved (fixed in 3.2.39-1)
bullseye: resolved (fixed in 3.2.39-1)
forky: resolved (fixed in 3.2.39-1)
sid: resolved (fixed in 3.2.39-1)
trixie: resolved (fixed in 3.2.39-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0871 kernel: race condition with PTRACE_SETREGS [fedora-all]
bugzilla·2013-02-16·CVSS 6.9
CVE-2013-0871 [MEDIUM] CVE-2013-0871 kernel: race condition with PTRACE_SETREGS [fedora-all]
CVE-2013-0871 kernel: race condition with PTRACE_SETREGS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects mul
Bugzilla
CVE-2013-0871 kernel: race condition with PTRACE_SETREGS
bugzilla·2013-02-16·CVSS 6.9
CVE-2013-0871 [MEDIUM] CVE-2013-0871 kernel: race condition with PTRACE_SETREGS
CVE-2013-0871 kernel: race condition with PTRACE_SETREGS
A race conditon in ptrace can lead to kernel stack corruption and arbitrary kernel-mode code execution. A local unprivileged user could use this flaw to elevate his privileges.
References:
http://seclists.org/oss-sec/2013/q1/326
Upstream fixes:
910ffdb18a6408e14febbb6e4b6840fd2c928c82
9899d11f654474d2d54ea52ceaa2a1f4db3abd68
9067ac85d533651b98c2ff903182a20cbb361fcb
Discussion:
Created kernel tracking bugs for this issue
Affects: fedora-all [bug 911942]
---
Statement:
This issue did affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2. Future updates may address this issue.
Please note that while a public non-weaponized exploit exists, according to our testing t
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=9899d11f654474d2d54ea52ceaa2a1f4db3abd68http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-04/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0567.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0661.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0662.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0695.htmlhttp://www.debian.org/security/2013/dsa-2632http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.5http://www.openwall.com/lists/oss-security/2013/02/15/16http://www.ubuntu.com/usn/USN-1736-1http://www.ubuntu.com/usn/USN-1737-1http://www.ubuntu.com/usn/USN-1738-1http://www.ubuntu.com/usn/USN-1739-1http://www.ubuntu.com/usn/USN-1740-1http://www.ubuntu.com/usn/USN-1741-1http://www.ubuntu.com/usn/USN-1742-1http://www.ubuntu.com/usn/USN-1743-1http://www.ubuntu.com/usn/USN-1744-1http://www.ubuntu.com/usn/USN-1745-1https://bugzilla.redhat.com/show_bug.cgi?id=911937https://github.com/torvalds/linux/commit/9899d11f654474d2d54ea52ceaa2a1f4db3abd68http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=9899d11f654474d2d54ea52ceaa2a1f4db3abd68http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-04/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0567.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0661.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0662.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0695.htmlhttp://www.debian.org/security/2013/dsa-2632http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.5http://www.openwall.com/lists/oss-security/2013/02/15/16http://www.ubuntu.com/usn/USN-1736-1http://www.ubuntu.com/usn/USN-1737-1http://www.ubuntu.com/usn/USN-1738-1http://www.ubuntu.com/usn/USN-1739-1http://www.ubuntu.com/usn/USN-1740-1http://www.ubuntu.com/usn/USN-1741-1http://www.ubuntu.com/usn/USN-1742-1http://www.ubuntu.com/usn/USN-1743-1http://www.ubuntu.com/usn/USN-1744-1http://www.ubuntu.com/usn/USN-1745-1https://bugzilla.redhat.com/show_bug.cgi?id=911937https://github.com/torvalds/linux/commit/9899d11f654474d2d54ea52ceaa2a1f4db3abd68
2013-02-18
Published