CVE-2013-1774
published 2013-02-28CVE-2013-1774: The chase_port function in drivers/usb/serial/io_ti.c in the Linux kernel before 3.7.4 allows local users to cause a denial of service (NULL pointer…
PriorityP413medium4CVSS 2.0
AVLACHAuNCNINAC
EPSS
0.39%
31.1th percentile
The chase_port function in drivers/usb/serial/io_ti.c in the Linux kernel before 3.7.4 allows local users to cause a denial of service (NULL pointer dereference and system crash) via an attempted /dev/ttyUSB read or write operation on a disconnected Edgeport USB serial converter.
Affected
151 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.38-1 (bookworm) | linux 3.2.38-1 (bookworm) |
| linux | linux_kernel | <= 3.7.3 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:L/AC:H/Au:N/C:N/I:N/A:C
osv4.0MEDIUM
vendor_ubuntu6.9MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2013-04-25·CVSS 1.9
CVE-2012-6542 [LOW] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered an information leak in the Linux kernel's
getsockname implementation for Logical Link Layer (llc) sockets. A local
user could exploit this flaw to examine some of the kernel's stack memory.
(CVE-2012-6542)
Mathias Krause discovered information leaks in the Linux kernel's Bluetooth
Logical Link Control and Adaptation Protocol (L2CAP) implementation. A
local user could exploit these flaws to examine some of the kernel's stack
memory. (CVE-2012-6544)
Mathias Krause discovered information leaks in the Linux kernel's Bluetooth
RFCOMM protocol implementation. A local user could exploit these flaws to
examine parts of kernel memory. (CVE-2012-6545)
Mathias Krause dis
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-04-19·CVSS 1.9
CVE-2012-6542 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered an information leak in the Linux kernel's
getsockname implementation for Logical Link Layer (llc) sockets. A local
user could exploit this flaw to examine some of the kernel's stack memory.
(CVE-2012-6542)
Mathias Krause discovered information leaks in the Linux kernel's Bluetooth
Logical Link Control and Adaptation Protocol (L2CAP) implementation. A
local user could exploit these flaws to examine some of the kernel's stack
memory. (CVE-2012-6544)
Mathias Krause discovered information leaks in the Linux kernel's Bluetooth
RFCOMM protocol implementation. A local user could exploit these flaws to
examine parts of kernel memory. (CVE-2012-6545)
Mathias Krause discovere
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-03-26·CVSS 6.2
CVE-2013-0228 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Jones discovered a flaw with the xen_iret function in Linux kernel's
Xen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged
guest OS user could exploit this flaw to cause a denial of service (crash
the system) or gain guest OS privilege. (CVE-2013-0228)
A flaw was reported in the permission checks done by the Linux kernel for
/dev/cpu/*/msr. A local root user with all capabilities dropped could
exploit this flaw to execute code with full root capabilities.
(CVE-2013-0268)
A flaw was discovered in the Linux kernel's vhost driver used to accelerate
guest networking in KVM based virtual machines. A privileged guest user
could exploit this flaw to crash the host s
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-03-18·CVSS 4.9
CVE-2013-0190 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Cooper of Citrix reported a Xen stack corruption in the Linux
kernel. An unprivileged user in a 32bit PVOPS guest can cause the guest
kernel to crash, or operate erroneously. (CVE-2013-0190)
A failure to validate input was discovered in the Linux kernel's Xen
netback (network backend) driver. A user in a guest OS may exploit this
flaw to cause a denial of service to the guest OS and other guest domains.
(CVE-2013-0216)
A memory leak was discovered in the Linux kernel's Xen netback (network
backend) driver. A user in a guest OS could trigger this flaw to cause a
denial of service on the system. (CVE-2013-0217)
Andrew Jones discovered a flaw with the xen_iret function in Linux kernel's
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2013-02-22·CVSS 6.9
CVE-2013-0871 [MEDIUM] Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to run programs as an administrator.
Suleiman Souhlal, Salman Qazi, Aaron Durbin and Michael Davidson discovered
a race condition in the Linux kernel's ptrace syscall. An unprivileged
local attacker could exploit this flaw to run programs as an administrator.
(CVE-2013-0871)
A flaw was discovered in the Edgeort USB serial converter driver when the
device is disconnected while it is in use. A local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2013-1774)
A flaw was discovered in the ChipIdea Highspeed Dual Role and ChipIdea host
controller drivers in the Linux kernel. A local user could use this flaw to
cause a denial of service (system crash). (CVE-2013-2058)
Instructions: Afte
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2013-02-22·CVSS 6.9
CVE-2013-0871 [MEDIUM] Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to run programs as an administrator.
Suleiman Souhlal, Salman Qazi, Aaron Durbin and Michael Davidson discovered
a race condition in the Linux kernel's ptrace syscall. An unprivileged
local attacker could exploit this flaw to run programs as an administrator.
(CVE-2013-0871)
A flaw was discovered in the Edgeort USB serial converter driver when the
device is disconnected while it is in use. A local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2013-1774)
A flaw was discovered in the ChipIdea Highspeed Dual Role and ChipIdea host
controller drivers in the Linux kernel. A local user could use this flaw to
cause a denial of service (system crash). (CVE-2013-2058)
Instructions: After a stan
Ubuntu
Linux kernel (Quantal HWE) vulnerability
vendor_ubuntu·2013-02-22·CVSS 6.9
CVE-2013-0871 [MEDIUM] Linux kernel (Quantal HWE) vulnerability
Title: Linux kernel (Quantal HWE) vulnerability
Summary: The system could be made to run programs as an administrator.
Suleiman Souhlal, Salman Qazi, Aaron Durbin and Michael Davidson discovered
a race condition in the Linux kernel's ptrace syscall. An unprivileged
local attacker could exploit this flaw to run programs as an administrator.
(CVE-2013-0871)
A flaw was discovered in the Edgeort USB serial converter driver when the
device is disconnected while it is in use. A local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2013-1774)
A flaw was discovered in the ChipIdea Highspeed Dual Role and ChipIdea host
controller drivers in the Linux kernel. A local user could use this flaw to
cause a denial of service (system crash). (CVE-2013-2058)
Instructions
Red Hat
Kernel: USB io_ti driver NULL pointer dereference in routine chase_port
vendor_redhat·2013-01-18·CVSS 4.0
CVE-2013-1774 [MEDIUM] CWE-476 Kernel: USB io_ti driver NULL pointer dereference in routine chase_port
Kernel: USB io_ti driver NULL pointer dereference in routine chase_port
The chase_port function in drivers/usb/serial/io_ti.c in the Linux kernel before 3.7.4 allows local users to cause a denial of service (NULL pointer dereference and system crash) via an attempted /dev/ttyUSB read or write operation on a disconnected Edgeport USB serial converter.
Statement: This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5.
This issue affects the version of Linux kernel as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise MRG 2 may address this issue.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2013-1774: linux - The chase_port function in drivers/usb/serial/io_ti.c in the Linux kernel before...
vendor_debian·2013·CVSS 4.0
CVE-2013-1774 [MEDIUM] CVE-2013-1774: linux - The chase_port function in drivers/usb/serial/io_ti.c in the Linux kernel before...
The chase_port function in drivers/usb/serial/io_ti.c in the Linux kernel before 3.7.4 allows local users to cause a denial of service (NULL pointer dereference and system crash) via an attempted /dev/ttyUSB read or write operation on a disconnected Edgeport USB serial converter.
Scope: local
bookworm: resolved (fixed in 3.2.38-1)
bullseye: resolved (fixed in 3.2.38-1)
forky: resolved (fixed in 3.2.38-1)
sid: resolved (fixed in 3.2.38-1)
trixie: resolved (fixed in 3.2.38-1)
GHSA
GHSA-qw67-7w8x-89v6: The chase_port function in drivers/usb/serial/io_ti
ghsa_unreviewed·2022-05-13
CVE-2013-1774 [MEDIUM] GHSA-qw67-7w8x-89v6: The chase_port function in drivers/usb/serial/io_ti
The chase_port function in drivers/usb/serial/io_ti.c in the Linux kernel before 3.7.4 allows local users to cause a denial of service (NULL pointer dereference and system crash) via an attempted /dev/ttyUSB read or write operation on a disconnected Edgeport USB serial converter.
OSV
CVE-2013-1774: The chase_port function in drivers/usb/serial/io_ti
osv·2013-02-28·CVSS 4.0
CVE-2013-1774 [MEDIUM] CVE-2013-1774: The chase_port function in drivers/usb/serial/io_ti
The chase_port function in drivers/usb/serial/io_ti.c in the Linux kernel before 3.7.4 allows local users to cause a denial of service (NULL pointer dereference and system crash) via an attempted /dev/ttyUSB read or write operation on a disconnected Edgeport USB serial converter.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1ee0a224bc9aad1de496c795f96bc6ba2c394811http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0744.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.4http://www.openwall.com/lists/oss-security/2013/02/27/29http://www.ubuntu.com/usn/USN-1805-1http://www.ubuntu.com/usn/USN-1808-1http://xorl.wordpress.com/2013/05/18/cve-2013-1774-linux-kernel-edgeport-usb-serial-converter-null-pointer-dereference/https://bugzilla.redhat.com/show_bug.cgi?id=916191https://github.com/torvalds/linux/commit/1ee0a224bc9aad1de496c795f96bc6ba2c394811http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1ee0a224bc9aad1de496c795f96bc6ba2c394811http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0744.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.4http://www.openwall.com/lists/oss-security/2013/02/27/29http://www.ubuntu.com/usn/USN-1805-1http://www.ubuntu.com/usn/USN-1808-1http://xorl.wordpress.com/2013/05/18/cve-2013-1774-linux-kernel-edgeport-usb-serial-converter-null-pointer-dereference/https://bugzilla.redhat.com/show_bug.cgi?id=916191https://github.com/torvalds/linux/commit/1ee0a224bc9aad1de496c795f96bc6ba2c394811
2013-02-28
Published