CVE-2013-1928
published 2013-04-29CVE-2013-1928: The do_video_set_spu_palette function in fs/compat_ioctl.c in the Linux kernel before 3.6.5 on unspecified architectures lacks a certain error check, which…
PriorityP415medium4.7CVSS 2.0
AVLACMAuNCCINAN
EPSS
0.35%
27.2th percentile
The do_video_set_spu_palette function in fs/compat_ioctl.c in the Linux kernel before 3.6.5 on unspecified architectures lacks a certain error check, which might allow local users to obtain sensitive information from kernel stack memory via a crafted VIDEO_SET_SPU_PALETTE ioctl call on a /dev/dvb device.
Affected
172 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.35-1 (bookworm) | linux 3.2.35-1 (bookworm) |
| linux | linux_kernel | <= 3.6.4 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:C/I:N/A:N
ghsa7.5HIGH
osv4.7MEDIUM
vendor_ubuntu4.9MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2013-05-16·CVSS 1.9
CVE-2012-6549 [LOW] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered an information leak in the Linux kernel's ISO
9660 CDROM file system driver. A local user could exploit this flaw to
examine some of the kernel's heap memory. (CVE-2012-6549)
Mathias Krause discovered a flaw in xfrm_user in the Linux kernel. A local
attacker with NET_ADMIN capability could potentially exploit this flaw to
escalate privileges. (CVE-2013-1826)
A buffer overflow was discovered in the Linux Kernel's USB subsystem for
devices reporting the cdc-wdm class. A specially crafted USB device when
plugged-in could cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2013-1860)
An information leak was discovered in the Linux ker
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-05-15·CVSS 1.9
CVE-2012-6549 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered an information leak in the Linux kernel's ISO
9660 CDROM file system driver. A local user could exploit this flaw to
examine some of the kernel's heap memory. (CVE-2012-6549)
Mathias Krause discovered a flaw in xfrm_user in the Linux kernel. A local
attacker with NET_ADMIN capability could potentially exploit this flaw to
escalate privileges. (CVE-2013-1826)
A buffer overflow was discovered in the Linux Kernel's USB subsystem for
devices reporting the cdc-wdm class. A specially crafted USB device when
plugged-in could cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2013-1860)
An information leak was discovered in the Linux kernel's
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2013-01-22·CVSS 4.9
CVE-2012-0957 [MEDIUM] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Brad Spengler discovered a flaw in the Linux kernel's uname system call. An
unprivileged user could exploit this flaw to read kernel stack memory.
(CVE-2012-0957)
Jon Howell reported a flaw in the Linux kernel's KVM (Kernel-based virtual
machine) subsystem's handling of the XSAVE feature. On hosts, using qemu
userspace, without the XSAVE feature an unprivileged local attacker could
exploit this flaw to crash the system. (CVE-2012-4461)
Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)
A flaw was discovered in the Linux kernel's handling o
Debian
CVE-2013-1928: linux - The do_video_set_spu_palette function in fs/compat_ioctl.c in the Linux kernel b...
vendor_debian·2013·CVSS 4.7
CVE-2013-1928 [MEDIUM] CVE-2013-1928: linux - The do_video_set_spu_palette function in fs/compat_ioctl.c in the Linux kernel b...
The do_video_set_spu_palette function in fs/compat_ioctl.c in the Linux kernel before 3.6.5 on unspecified architectures lacks a certain error check, which might allow local users to obtain sensitive information from kernel stack memory via a crafted VIDEO_SET_SPU_PALETTE ioctl call on a /dev/dvb device.
Scope: local
bookworm: resolved (fixed in 3.2.35-1)
bullseye: resolved (fixed in 3.2.35-1)
forky: resolved (fixed in 3.2.35-1)
sid: resolved (fixed in 3.2.35-1)
trixie: resolved (fixed in 3.2.35-1)
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2012-12-19·CVSS 1.9
CVE-2012-4508 [LOW] Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash under certain conditions.
Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)
A flaw was discovered in the Linux kernel's handling of new hot-plugged
memory. An unprivileged local user could exploit this flaw to cause a
denial of service by crashing the system. (CVE-2012-5517)
An information leak was discovered in the Linux kernel's /dev/dvb device. A
local user could exploit this flaw to obtain sensitive information from the
kernel's stack memory. (CVE-2013-1928)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary chang
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2012-12-19·CVSS 1.9
CVE-2012-4508 [LOW] Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to crash under certain conditions.
Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)
A flaw was discovered in the Linux kernel's handling of new hot-plugged
memory. An unprivileged local user could exploit this flaw to cause a
denial of service by crashing the system. (CVE-2012-5517)
An information leak was discovered in the Linux kernel's /dev/dvb device. A
local user could exploit this flaw to obtain sensitive information from the
kernel's stack memory. (CVE-2013-1928)
Instructions: After a standard system update you need to reboot your computer to make
all the necessa
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-11-30·CVSS 4.9
CVE-2012-0957 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Brad Spengler discovered a flaw in the Linux kernel's uname system call. An
unprivileged user could exploit this flaw to read kernel stack memory.
(CVE-2012-0957)
Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)
Rodrigo Freire discovered a flaw in the Linux kernel's TCP illinois
congestion control algorithm. A local attacker could use this to cause a
denial of service. (CVE-2012-4565)
Mathias Krause discovered a flaw in the Linux kernel's XFRM netlink
interface. A local user with the NET_ADMIN capability could exploit this
flaw to leak the contents of
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-11-30·CVSS 4.9
CVE-2012-0957 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Brad Spengler discovered a flaw in the Linux kernel's uname system call. An
unprivileged user could exploit this flaw to read kernel stack memory.
(CVE-2012-0957)
Rodrigo Freire discovered a flaw in the Linux kernel's TCP illinois
congestion control algorithm. A local attacker could use this to cause a
denial of service. (CVE-2012-4565)
Mathias Krause discovered a flaw in the Linux kernel's XFRM netlink
interface. A local user with the NET_ADMIN capability could exploit this
flaw to leak the contents of kernel memory. (CVE-2012-6536)
Mathias Krause discovered several errors in the Linux kernel's xfrm_user
implementation. A local attacker could exploit these flaws to examine parts
of kernel m
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-11-30·CVSS 4.9
CVE-2012-0957 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Brad Spengler discovered a flaw in the Linux kernel's uname system call. An
unprivileged user could exploit this flaw to read kernel stack memory.
(CVE-2012-0957)
Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)
Rodrigo Freire discovered a flaw in the Linux kernel's TCP illinois
congestion control algorithm. A local attacker could use this to cause a
denial of service. (CVE-2012-4565)
Mathias Krause discovered a flaw in the Linux kernel's XFRM netlink
interface. A local user with the NET_ADMIN capability could exploit this
flaw to leak the con
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2012-11-30·CVSS 4.9
CVE-2012-0957 [MEDIUM] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Brad Spengler discovered a flaw in the Linux kernel's uname system call. An
unprivileged user could exploit this flaw to read kernel stack memory.
(CVE-2012-0957)
Rodrigo Freire discovered a flaw in the Linux kernel's TCP illinois
congestion control algorithm. A local attacker could use this to cause a
denial of service. (CVE-2012-4565)
Mathias Krause discovered a flaw in the Linux kernel's XFRM netlink
interface. A local user with the NET_ADMIN capability could exploit this
flaw to leak the contents of kernel memory. (CVE-2012-6536)
Mathias Krause discovered several errors in the Linux kernel's xfrm_user
implementation. A local attacker could exploit these flaws to examin
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-11-30·CVSS 4.9
CVE-2012-0957 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Brad Spengler discovered a flaw in the Linux kernel's uname system call. An
unprivileged user could exploit this flaw to read kernel stack memory.
(CVE-2012-0957)
Rodrigo Freire discovered a flaw in the Linux kernel's TCP illinois
congestion control algorithm. A local attacker could use this to cause a
denial of service. (CVE-2012-4565)
Mathias Krause discovered a flaw in the Linux kernel's XFRM netlink
interface. A local user with the NET_ADMIN capability could exploit this
flaw to leak the contents of kernel memory. (CVE-2012-6536)
Mathias Krause discovered several errors in the Linux kernel's xfrm_user
implementation. A local attacker could exploit these flaws to examine parts
of
Red Hat
Kernel: information leak in fs/compat_ioctl.c VIDEO_SET_SPU_PALETTE
vendor_redhat·2012-10-25·CVSS 4.7
CVE-2013-1928 [MEDIUM] Kernel: information leak in fs/compat_ioctl.c VIDEO_SET_SPU_PALETTE
Kernel: information leak in fs/compat_ioctl.c VIDEO_SET_SPU_PALETTE
The do_video_set_spu_palette function in fs/compat_ioctl.c in the Linux kernel before 3.6.5 on unspecified architectures lacks a certain error check, which might allow local users to obtain sensitive information from kernel stack memory via a crafted VIDEO_SET_SPU_PALETTE ioctl call on a /dev/dvb device.
Statement: This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2.
This issue affects the version of Linux kernel as shipped with
Red Hat Enterprise Linux 6. Future kernel updates for Red Hat Enterprise Linux 6
may address this issue.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG
GHSA
GHSA-fj24-32r9-v783: The do_video_set_spu_palette function in fs/compat_ioctl
ghsa_unreviewed·2022-05-14
CVE-2013-1928 [MEDIUM] CWE-200 GHSA-fj24-32r9-v783: The do_video_set_spu_palette function in fs/compat_ioctl
The do_video_set_spu_palette function in fs/compat_ioctl.c in the Linux kernel before 3.6.5 on unspecified architectures lacks a certain error check, which might allow local users to obtain sensitive information from kernel stack memory via a crafted VIDEO_SET_SPU_PALETTE ioctl call on a /dev/dvb device.
GHSA
python-gnupg's shell_quote function does not properly quote strings
ghsa·2018-11-06·CVSS 7.5
CVE-2014-1927 [HIGH] CWE-20 python-gnupg's shell_quote function does not properly quote strings
python-gnupg's shell_quote function does not properly quote strings
The shell_quote function in python-gnupg 0.3.5 does not properly quote strings, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "$(" command-substitution sequences, a different vulnerability than CVE-2014-1928. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.
GHSA
python-gnupg's shell_quote function does not properly escape characters
ghsa·2018-11-06·CVSS 7.5
CVE-2014-1928 [HIGH] CWE-20 python-gnupg's shell_quote function does not properly escape characters
python-gnupg's shell_quote function does not properly escape characters
The shell_quote function in python-gnupg 0.3.5 does not properly escape characters, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "\" (backslash) characters to form multi-command sequences, a different vulnerability than CVE-2014-1927. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.
OSV
CVE-2013-1928: The do_video_set_spu_palette function in fs/compat_ioctl
osv·2013-04-29·CVSS 4.7
CVE-2013-1928 [MEDIUM] CVE-2013-1928: The do_video_set_spu_palette function in fs/compat_ioctl
The do_video_set_spu_palette function in fs/compat_ioctl.c in the Linux kernel before 3.6.5 on unspecified architectures lacks a certain error check, which might allow local users to obtain sensitive information from kernel stack memory via a crafted VIDEO_SET_SPU_PALETTE ioctl call on a /dev/dvb device.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-7323 CVE-2014-1927 CVE-2014-1928 CVE-2014-1929 python-gnupg: incorrect fix against shell injection
bugzilla·2014-02-05·CVSS 7.5
CVE-2013-7323 [HIGH] CVE-2013-7323 CVE-2014-1927 CVE-2014-1928 CVE-2014-1929 python-gnupg: incorrect fix against shell injection
CVE-2013-7323 CVE-2014-1927 CVE-2014-1928 CVE-2014-1929 python-gnupg: incorrect fix against shell injection
It was found [1] that the fix for improved shell quoting to guard against shell injection, released in version 0.3.5 [2] of python-gnupg, is not sufficient.
This issue has been reported upstream [3].
[1] http://seclists.org/oss-sec/2014/q1/243
[2] https://code.google.com/p/python-gnupg/
[3] https://code.google.com/p/python-gnupg/issues/detail?id=98#c4
Discussion:
Created python-gnupg tracking bugs for this issue:
Affects: fedora-all [bug 1061600]
---
updates pushed to updates-testing for f19,f20,el6 (and built in rawhide)
---
This was assigned multiple CVE numbers:
CVE-2013-7323 Unrestricted use of unquoted strings in a shell,
within version 0.3.4
CVE-2014-1927 Erroneous
Bugzilla
CVE-2013-1928 Kernel: information leak in fs/compat_ioctl.c VIDEO_SET_SPU_PALETTE
bugzilla·2013-04-08·CVSS 4.7
CVE-2013-1928 [MEDIUM] CVE-2013-1928 Kernel: information leak in fs/compat_ioctl.c VIDEO_SET_SPU_PALETTE
CVE-2013-1928 Kernel: information leak in fs/compat_ioctl.c VIDEO_SET_SPU_PALETTE
Linux kernel built with Digital Video Broadcasting(CONFIG_DVB) support are
vulnerable to an information leak issue. The leak could occurs via an
ioctl(VIDEO_SET_SPU_PALETTE) call on a device file under - /dev/dvb/ - tree.
Upstream fix:
-> https://git.kernel.org/linus/12176503366885edd542389eed3aaf94be163fdb
Reference:
-> http://www.openwall.com/lists/oss-security/2013/04/05/3
Discussion:
Statement:
This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2.
This issue affects the version of Linux kernel as shipped with
Red Hat Enterprise Linux 6. Future kernel updates for Red Hat Enterprise Linux 6
may address this issue.
---
Bugzilla
CVE-2013-0401 OpenJDK: sun.awt.datatransfer.ClassLoaderObjectInputStream class may incorrectly invoke the system class loader (CanSecWest 2013, AWT, 8009305)
bugzilla·2013-03-11·CVSS 10.0
CVE-2013-0401 [CRITICAL] CVE-2013-0401 OpenJDK: sun.awt.datatransfer.ClassLoaderObjectInputStream class may incorrectly invoke the system class loader (CanSecWest 2013, AWT, 8009305)
CVE-2013-0401 OpenJDK: sun.awt.datatransfer.ClassLoaderObjectInputStream class may incorrectly invoke the system class loader (CanSecWest 2013, AWT, 8009305)
The sun.awt.datatransfer.ClassLoaderObjectInputStream class may incorrectly
invoke the system class loader. An untrusted Java application or applet
could possibly use this flaw to bypass certain Java sandbox restrictions.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0401
[2] http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157
[3] http://www.zdnet.com/pwn2own-down-go-all-the-browsers-7000012283/
[4] https://twitter.com/thezdi/status/309784608508100608
Discussion:
Public now via Oracle Java SE CPU April 2014:
http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=12176503366885edd542389eed3aaf94be163fdbhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00000.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1645.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.6.5http://www.openwall.com/lists/oss-security/2013/04/06/2http://www.openwall.com/lists/oss-security/2013/04/09/6http://www.ubuntu.com/usn/USN-1829-1https://bugzilla.redhat.com/show_bug.cgi?id=949567https://github.com/torvalds/linux/commit/12176503366885edd542389eed3aaf94be163fdbhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=12176503366885edd542389eed3aaf94be163fdbhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00000.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1645.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.6.5http://www.openwall.com/lists/oss-security/2013/04/06/2http://www.openwall.com/lists/oss-security/2013/04/09/6http://www.ubuntu.com/usn/USN-1829-1https://bugzilla.redhat.com/show_bug.cgi?id=949567https://github.com/torvalds/linux/commit/12176503366885edd542389eed3aaf94be163fdb
2013-04-29
Published