CVE-2013-1848
published 2013-03-22CVE-2013-1848: fs/ext3/super.c in the Linux kernel before 3.8.4 uses incorrect arguments to functions in certain circumstances related to printk input, which allows local…
PriorityP423medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.58%
44.3th percentile
fs/ext3/super.c in the Linux kernel before 3.8.4 uses incorrect arguments to functions in certain circumstances related to printk input, which allows local users to conduct format-string attacks and possibly gain privileges via a crafted application.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.41-1 (bookworm) | linux 3.2.41-1 (bookworm) |
| linux | linux_kernel | <= 3.8.3 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.2.41-1 | 3.2.41-1 |
| linux | linux_kernel | >= 0 < 3.2.41-1 | 3.2.41-1 |
| linux | linux_kernel | >= 0 < 3.2.41-1 | 3.2.41-1 |
| linux | linux_kernel | >= 0 < 3.2.41-1 | 3.2.41-1 |
CVSS provenance
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
osv6.2MEDIUM
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
vendor_ubuntu1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-05-02·CVSS 1.9
CVE-2012-6548 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered an information leak in the Linux kernel's UDF
file system implementation. A local user could exploit this flaw to examine
some of the kernel's heap memory. (CVE-2012-6548)
Mathias Krause discovered an information leak in the Linux kernel's ISO
9660 CDROM file system driver. A local user could exploit this flaw to
examine some of the kernel's heap memory. (CVE-2012-6549)
An integer overflow was discovered in the Direct Rendering Manager (DRM)
subsystem for the i915 video driver in the Linux kernel. A local user could
exploit this flaw to cause a denial of service (crash) or potentially
escalate privileges. (CVE-2013-0913)
Andrew Honig discovered a flaw in guest OS ti
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-05-02·CVSS 1.9
CVE-2012-6548 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered an information leak in the Linux kernel's UDF
file system implementation. A local user could exploit this flaw to examine
some of the kernel's heap memory. (CVE-2012-6548)
Mathias Krause discovered an information leak in the Linux kernel's ISO
9660 CDROM file system driver. A local user could exploit this flaw to
examine some of the kernel's heap memory. (CVE-2012-6549)
An integer overflow was discovered in the Direct Rendering Manager (DRM)
subsystem for the i915 video driver in the Linux kernel. A local user could
exploit this flaw to cause a denial of service (crash) or potentially
escalate privileges. (CVE-2013-0913)
A format-string bug was discovered in
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2013-05-01·CVSS 1.9
CVE-2012-6548 [LOW] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered an information leak in the Linux kernel's UDF
file system implementation. A local user could exploit this flaw to examine
some of the kernel's heap memory. (CVE-2012-6548)
Mathias Krause discovered an information leak in the Linux kernel's ISO
9660 CDROM file system driver. A local user could exploit this flaw to
examine some of the kernel's heap memory. (CVE-2012-6549)
An integer overflow was discovered in the Direct Rendering Manager (DRM)
subsystem for the i915 video driver in the Linux kernel. A local user could
exploit this flaw to cause a denial of service (crash) or potentially
escalate privileges. (CVE-2013-0913)
Andrew Honig discovered a flaw
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-05-01·CVSS 1.9
CVE-2012-6548 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered an information leak in the Linux kernel's UDF
file system implementation. A local user could exploit this flaw to examine
some of the kernel's heap memory. (CVE-2012-6548)
Mathias Krause discovered an information leak in the Linux kernel's ISO
9660 CDROM file system driver. A local user could exploit this flaw to
examine some of the kernel's heap memory. (CVE-2012-6549)
An integer overflow was discovered in the Direct Rendering Manager (DRM)
subsystem for the i915 video driver in the Linux kernel. A local user could
exploit this flaw to cause a denial of service (crash) or potentially
escalate privileges. (CVE-2013-0913)
Andrew Honig discovered a use after f
Red Hat
kernel: ext3: format string issues
vendor_redhat·2013-03-18·CVSS 6.2
CVE-2013-1848 [MEDIUM] kernel: ext3: format string issues
kernel: ext3: format string issues
fs/ext3/super.c in the Linux kernel before 3.8.4 uses incorrect arguments to functions in certain circumstances related to printk input, which allows local users to conduct format-string attacks and possibly gain privileges via a crafted application.
Statement: This issue did not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5 because it did not backport the commit 4cf46b67eb that introduced this issue.
This issue affects the version of Linux kernel as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2 may address this issue.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2013-1848: linux - fs/ext3/super.c in the Linux kernel before 3.8.4 uses incorrect arguments to fun...
vendor_debian·2013·CVSS 6.2
CVE-2013-1848 [MEDIUM] CVE-2013-1848: linux - fs/ext3/super.c in the Linux kernel before 3.8.4 uses incorrect arguments to fun...
fs/ext3/super.c in the Linux kernel before 3.8.4 uses incorrect arguments to functions in certain circumstances related to printk input, which allows local users to conduct format-string attacks and possibly gain privileges via a crafted application.
Scope: local
bookworm: resolved (fixed in 3.2.41-1)
bullseye: resolved (fixed in 3.2.41-1)
forky: resolved (fixed in 3.2.41-1)
sid: resolved (fixed in 3.2.41-1)
trixie: resolved (fixed in 3.2.41-1)
GHSA
GHSA-vc5v-mx5f-p3gq: fs/ext3/super
ghsa_unreviewed·2022-05-17
CVE-2013-1848 [MEDIUM] CWE-20 GHSA-vc5v-mx5f-p3gq: fs/ext3/super
fs/ext3/super.c in the Linux kernel before 3.8.4 uses incorrect arguments to functions in certain circumstances related to printk input, which allows local users to conduct format-string attacks and possibly gain privileges via a crafted application.
OSV
CVE-2013-1848: fs/ext3/super
osv·2013-03-22·CVSS 6.2
CVE-2013-1848 [MEDIUM] CVE-2013-1848: fs/ext3/super
fs/ext3/super.c in the Linux kernel before 3.8.4 uses incorrect arguments to functions in certain circumstances related to printk input, which allows local users to conduct format-string attacks and possibly gain privileges via a crafted application.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1848 kernel: ext3: format string issues
bugzilla·2013-03-12·CVSS 6.2
CVE-2013-1848 [MEDIUM] CVE-2013-1848 kernel: ext3: format string issues
CVE-2013-1848 kernel: ext3: format string issues
ext3_msg() takes the printk prefix as the second parameter and the format string as the third parameter. Two callers of ext3_msg omit the prefix and pass the format string as the second parameter and the first parameter to the format string as the third parameter. In both cases this string comes from an arbitrary source.
An user able to mount ext3 filesystems could use this flaw to crash the system or, potentially, increase their privileges.
Upstream fix:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8d0c2d10dd72c5292eda7a06231056a4c972e4cc
Discussion:
Statement:
This issue did not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5 because it did not backport the commit 4cf4
arXiv
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
arxiv_fulltext·2022-04-26
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
## Abstract
This paper presents a systematic study on the security of modern file systems,
following a vulnerability-centric perspective. Specifically,
we collected 377 file system vulnerabilities committed to the CVE database in the past 20 years.
We characterize them from four dimensions that include why the vulnerabilities appear,
how the vulnerabilities can be exploited, what consequences can arise,
and how the vulnerabilities are fixed. This way, we build a deep understanding of
the attack surfaces faced by file systems, the threats imposed by the attack surfaces,
and the good and bad practices in mitigating the attacks in file systems. We envision that our study
will bring insights toward
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8d0c2d10dd72c5292eda7a06231056a4c972e4cchttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0928.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1026.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1051.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.4http://www.mandriva.com/security/advisories?name=MDVSA-2013:176http://www.openwall.com/lists/oss-security/2013/03/20/8http://www.ubuntu.com/usn/USN-1809-1http://www.ubuntu.com/usn/USN-1811-1http://www.ubuntu.com/usn/USN-1812-1http://www.ubuntu.com/usn/USN-1813-1http://www.ubuntu.com/usn/USN-1814-1https://bugzilla.redhat.com/show_bug.cgi?id=920783https://github.com/torvalds/linux/commit/8d0c2d10dd72c5292eda7a06231056a4c972e4cchttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8d0c2d10dd72c5292eda7a06231056a4c972e4cchttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0928.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1026.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1051.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.4http://www.mandriva.com/security/advisories?name=MDVSA-2013:176http://www.openwall.com/lists/oss-security/2013/03/20/8http://www.ubuntu.com/usn/USN-1809-1http://www.ubuntu.com/usn/USN-1811-1http://www.ubuntu.com/usn/USN-1812-1http://www.ubuntu.com/usn/USN-1813-1http://www.ubuntu.com/usn/USN-1814-1https://bugzilla.redhat.com/show_bug.cgi?id=920783https://github.com/torvalds/linux/commit/8d0c2d10dd72c5292eda7a06231056a4c972e4cc
2013-03-22
Published