CVE-2013-1827
published 2013-03-22CVE-2013-1827: net/dccp/ccid.h in the Linux kernel before 3.5.4 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash)…
PriorityP419medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.48%
38.9th percentile
net/dccp/ccid.h in the Linux kernel before 3.5.4 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability for a certain (1) sender or (2) receiver getsockopt call.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.29-1 (bookworm) | linux 3.2.29-1 (bookworm) |
| linux | linux_kernel | <= 3.5.3 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.2.29-1 | 3.2.29-1 |
| linux | linux_kernel | >= 0 < 3.2.29-1 | 3.2.29-1 |
| linux | linux_kernel | >= 0 < 3.2.29-1 | 3.2.29-1 |
| linux | linux_kernel | >= 0 < 3.2.29-1 | 3.2.29-1 |
CVSS provenance
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
osv6.2MEDIUM
vendor_ubuntu6.9MEDIUM
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2013-1827: linux - net/dccp/ccid.h in the Linux kernel before 3.5.4 allows local users to gain priv...
vendor_debian·2013·CVSS 6.2
CVE-2013-1827 [MEDIUM] CVE-2013-1827: linux - net/dccp/ccid.h in the Linux kernel before 3.5.4 allows local users to gain priv...
net/dccp/ccid.h in the Linux kernel before 3.5.4 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability for a certain (1) sender or (2) receiver getsockopt call.
Scope: local
bookworm: resolved (fixed in 3.2.29-1)
bullseye: resolved (fixed in 3.2.29-1)
forky: resolved (fixed in 3.2.29-1)
sid: resolved (fixed in 3.2.29-1)
trixie: resolved (fixed in 3.2.29-1)
Ubuntu
Linux kernel (EC2) vulnerability
vendor_ubuntu·2012-12-04·CVSS 4.7
CVE-2012-4565 [MEDIUM] Linux kernel (EC2) vulnerability
Title: Linux kernel (EC2) vulnerability
Summary: The system could be made to run programs as an administrator.
Rodrigo Freire discovered a flaw in the Linux kernel's TCP illinois
congestion control algorithm. A local attacker could use this to cause a
denial of service. (CVE-2012-4565)
Mathias Krause discovered an information leak in the Linux kernel's TUN/TAP
device driver. A local user could exploit this flaw to examine part of the
kernel's stack memory. (CVE-2012-6547)
Denys Fedoryshchenko discovered a flaw in the Linux kernel's TCP receive
processing for IPv4. A remote attacker could exploit this flaw to cause a
denial of service (kernel resource consumption) via a flood of SYN+FIN TCP
packets. (CVE-2012-6638)
A flaw was discovered in the requeuing of futexes in the Linux kernel.
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2012-11-30·CVSS 4.7
CVE-2012-4565 [MEDIUM] Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash under certain conditions.
Rodrigo Freire discovered a flaw in the Linux kernel's TCP illinois
congestion control algorithm. A local attacker could use this to cause a
denial of service. (CVE-2012-4565)
Mathias Krause discovered an information leak in the Linux kernel's TUN/TAP
device driver. A local user could exploit this flaw to examine part of the
kernel's stack memory. (CVE-2012-6547)
Denys Fedoryshchenko discovered a flaw in the Linux kernel's TCP receive
processing for IPv4. A remote attacker could exploit this flaw to cause a
denial of service (kernel resource consumption) via a flood of SYN+FIN TCP
packets. (CVE-2012-6638)
A flaw was discovered in the requeuing of futexes in the Linux kernel. A
local
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2012-10-12·CVSS 6.9
CVE-2012-2137 [MEDIUM] Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to crash under certain conditions.
A flaw was found in how the Linux kernel's KVM (Kernel-based Virtual
Machine) subsystem handled MSI (Message Signaled Interrupts). A local
unprivileged user could exploit this flaw to cause a denial of service or
potentially elevate privileges. (CVE-2012-2137)
Mathias Krause discover an error in Linux kernel's Datagram Congestion
Control Protocol (DCCP) Congestion Control Identifier (CCID) use. A local
attack could exploit this flaw to cause a denial of service (crash) and
potentially escalate privileges if the user can mmap page 0.
(CVE-2013-1827)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2012-10-12·CVSS 1.9
CVE-2012-3520 [LOW] Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to perform privileged actions as an administrator.
Pablo Neira Ayuso discovered a flaw in the credentials of netlink messages.
An unprivileged local attacker could exploit this by getting a netlink
based service, that relies on netlink credentials, to perform privileged
actions. (CVE-2012-3520)
Mathias Krause discovered information leak in the Linux kernel's compat
ioctl interface. A local user could exploit the flaw to examine parts of
kernel stack memory (CVE-2012-6539)
Mathias Krause discovered an information leak in the Linux kernel's
getsockopt for IP_VS_SO_GET_TIMEOUT. A local user could exploit this flaw
to examine parts of kernel stack memory. (CVE-2012-6540)
Mathias Krause discovered an information leak in th
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-10-11·CVSS 5.0
CVE-2012-2127 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vadim Ponomarev discovered a flaw in the Linux kernel causing a reference
leak when PID namespaces are used. A remote attacker could exploit this
flaw causing a denial of service. (CVE-2012-2127)
A flaw was found in how the Linux kernel's KVM (Kernel-based Virtual
Machine) subsystem handled MSI (Message Signaled Interrupts). A local
unprivileged user could exploit this flaw to cause a denial of service or
potentially elevate privileges. (CVE-2012-2137)
Mathias Krause discover an error in Linux kernel's Datagram Congestion
Control Protocol (DCCP) Congestion Control Identifier (CCID) use. A local
attack could exploit this flaw to cause a denial of service (crash) and
potentially escalate privil
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2012-10-09·CVSS 1.9
CVE-2012-3520 [LOW] Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to run actions or potentially programs as an
administrator.
Pablo Neira Ayuso discovered a flaw in the credentials of netlink messages.
An unprivileged local attacker could exploit this by getting a netlink
based service, that relies on netlink credentials, to perform privileged
actions. (CVE-2012-3520)
Mathias Krause discovered information leak in the Linux kernel's compat
ioctl interface. A local user could exploit the flaw to examine parts of
kernel stack memory (CVE-2012-6539)
Mathias Krause discovered an information leak in the Linux kernel's
getsockopt for IP_VS_SO_GET_TIMEOUT. A local user could exploit this flaw
to examine parts of kernel stack memory. (CVE-2012-6540)
Mathias Krause discovered an infor
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2012-10-03·CVSS 5.0
CVE-2012-2127 [MEDIUM] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vadim Ponomarev discovered a flaw in the Linux kernel causing a reference
leak when PID namespaces are used. A remote attacker could exploit this
flaw causing a denial of service. (CVE-2012-2127)
A flaw was found in how the Linux kernel's KVM (Kernel-based Virtual
Machine) subsystem handled MSI (Message Signaled Interrupts). A local
unprivileged user could exploit this flaw to cause a denial of service or
potentially elevate privileges. (CVE-2012-2137)
Mathias Krause discover an error in Linux kernel's Datagram Congestion
Control Protocol (DCCP) Congestion Control Identifier (CCID) use. A local
attack could exploit this flaw to cause a denial of service (crash) and
potentia
Red Hat
Kernel: dccp: check ccid before NULL poiter dereference
vendor_redhat·2012-08-15·CVSS 6.2
CVE-2013-1827 [MEDIUM] Kernel: dccp: check ccid before NULL poiter dereference
Kernel: dccp: check ccid before NULL poiter dereference
net/dccp/ccid.h in the Linux kernel before 3.5.4 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability for a certain (1) sender or (2) receiver getsockopt call.
Statement: This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2.
This issue affects the version of Linux kernel as shipped with Red Hat Enterprise Linux 6.
Package: kernel (Red Hat Enterprise Linux 5) - Affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
GHSA
GHSA-q6m9-q5p3-3c36: net/dccp/ccid
ghsa_unreviewed·2022-05-17
CVE-2013-1827 [MEDIUM] GHSA-q6m9-q5p3-3c36: net/dccp/ccid
net/dccp/ccid.h in the Linux kernel before 3.5.4 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability for a certain (1) sender or (2) receiver getsockopt call.
OSV
CVE-2013-1827: net/dccp/ccid
osv·2013-03-22·CVSS 6.2
CVE-2013-1827 [MEDIUM] CVE-2013-1827: net/dccp/ccid
net/dccp/ccid.h in the Linux kernel before 3.5.4 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability for a certain (1) sender or (2) receiver getsockopt call.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=276bdb82dedb290511467a5a4fdbe9f0b52dce6fhttp://rhn.redhat.com/errata/RHSA-2013-0744.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.5.4http://www.openwall.com/lists/oss-security/2013/03/07/2https://bugzilla.redhat.com/show_bug.cgi?id=919164https://github.com/torvalds/linux/commit/276bdb82dedb290511467a5a4fdbe9f0b52dce6fhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=276bdb82dedb290511467a5a4fdbe9f0b52dce6fhttp://rhn.redhat.com/errata/RHSA-2013-0744.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.5.4http://www.openwall.com/lists/oss-security/2013/03/07/2https://bugzilla.redhat.com/show_bug.cgi?id=919164https://github.com/torvalds/linux/commit/276bdb82dedb290511467a5a4fdbe9f0b52dce6f
2013-03-22
Published