CVE-2013-1929
published 2013-06-07CVE-2013-1929: Heap-based buffer overflow in the tg3_read_vpd function in drivers/net/ethernet/broadcom/tg3.c in the Linux kernel before 3.8.6 allows physically proximate…
PriorityP424medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.72%
50.2th percentile
Heap-based buffer overflow in the tg3_read_vpd function in drivers/net/ethernet/broadcom/tg3.c in the Linux kernel before 3.8.6 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via crafted firmware that specifies a long string in the Vital Product Data (VPD) data structure.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.8.11-1 (bookworm) | linux 3.8.11-1 (bookworm) |
| linux | linux_kernel | <= 3.8.5 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.8.11-1 | 3.8.11-1 |
| linux | linux_kernel | >= 0 < 3.8.11-1 | 3.8.11-1 |
| linux | linux_kernel | >= 0 < 3.8.11-1 | 3.8.11-1 |
| linux | linux_kernel | >= 0 < 3.8.11-1 | 3.8.11-1 |
| python-gnupg_project | python-gnupg | >= 0.3.5 < 0.3.7 | 0.3.7 |
CVSS provenance
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
ghsa7.5HIGH
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
vendor_ubuntu4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w3j5-8m88-j68f: Heap-based buffer overflow in the tg3_read_vpd function in drivers/net/ethernet/broadcom/tg3
ghsa_unreviewed·2022-05-17
CVE-2013-1929 [MEDIUM] CWE-119 GHSA-w3j5-8m88-j68f: Heap-based buffer overflow in the tg3_read_vpd function in drivers/net/ethernet/broadcom/tg3
Heap-based buffer overflow in the tg3_read_vpd function in drivers/net/ethernet/broadcom/tg3.c in the Linux kernel before 3.8.6 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via crafted firmware that specifies a long string in the Vital Product Data (VPD) data structure.
GHSA
python-gnupg vulnerable to shell injection
ghsa·2018-11-06·CVSS 7.5
CVE-2014-1929 [HIGH] CWE-20 python-gnupg vulnerable to shell injection
python-gnupg vulnerable to shell injection
python-gnupg 0.3.5 and 0.3.6 allow for shell injection via a failure to escape backslashes in the `shell_quote()` function. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.
OSV
CVE-2013-1929: Heap-based buffer overflow in the tg3_read_vpd function in drivers/net/ethernet/broadcom/tg3
osv·2013-06-07·CVSS 4.4
CVE-2013-1929 [MEDIUM] CVE-2013-1929: Heap-based buffer overflow in the tg3_read_vpd function in drivers/net/ethernet/broadcom/tg3
Heap-based buffer overflow in the tg3_read_vpd function in drivers/net/ethernet/broadcom/tg3.c in the Linux kernel before 3.8.6 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via crafted firmware that specifies a long string in the Vital Product Data (VPD) data structure.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-05-30·CVSS 4.4
CVE-2013-1929 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An flaw was discovered in the Linux kernel's perf_events interface. A local
user could exploit this flaw to escalate privileges on the system.
(CVE-2013-2094)
A buffer overflow vulnerability was discovered in the Broadcom tg3 ethernet
driver for the Linux kernel. A local user could exploit this flaw to cause
a denial of service (crash the system) or potentially escalate privileges
on the system. (CVE-2013-1929)
A flaw was discovered in the Linux kernel's ftrace subsystem interface. A
local user could exploit this flaw to cause a denial of service (system
crash). (CVE-2013-3301)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary cha
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-05-28·CVSS 4.4
CVE-2013-1929 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An flaw was discovered in the Linux kernel's perf_events interface. A local
user could exploit this flaw to escalate privileges on the system.
(CVE-2013-2094)
Andy Lutomirski discover an error in the Linux kernel's credential handling
on unix sockets. A local user could exploit this flaw to gain
administrative privileges. (CVE-2013-1979)
A buffer overflow vulnerability was discovered in the Broadcom tg3 ethernet
driver for the Linux kernel. A local user could exploit this flaw to cause
a denial of service (crash the system) or potentially escalate privileges
on the system. (CVE-2013-1929)
An information leak was discovered in the Linux kernel's tkill and tgkill
system calls when used
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-05-24·CVSS 4.4
CVE-2013-1929 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A buffer overflow vulnerability was discovered in the Broadcom tg3 ethernet
driver for the Linux kernel. A local user could exploit this flaw to cause
a denial of service (crash the system) or potentially escalate privileges
on the system. (CVE-2013-1929)
A flaw was discovered in the Linux kernel's ftrace subsystem interface. A
local user could exploit this flaw to cause a denial of service (system
crash). (CVE-2013-3301)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third part
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2013-05-24·CVSS 4.4
CVE-2013-1929 [MEDIUM] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A buffer overflow vulnerability was discovered in the Broadcom tg3 ethernet
driver for the Linux kernel. A local user could exploit this flaw to cause
a denial of service (crash the system) or potentially escalate privileges
on the system. (CVE-2013-1929)
A flaw was discovered in the Linux kernel's ftrace subsystem interface. A
local user could exploit this flaw to cause a denial of service (system
crash). (CVE-2013-3301)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-05-24·CVSS 4.4
CVE-2013-1929 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Lutomirski discover an error in the Linux kernel's credential handling
on unix sockets. A local user could exploit this flaw to gain
administrative privileges. (CVE-2013-1979)
A buffer overflow vulnerability was discovered in the Broadcom tg3 ethernet
driver for the Linux kernel. A local user could exploit this flaw to cause
a denial of service (crash the system) or potentially escalate privileges
on the system. (CVE-2013-1929)
An information leak was discovered in the Linux kernel's tkill and tgkill
system calls when used from compat processes. A local user could exploit
this flaw to examine potentially sensitive kernel memory. (CVE-2013-2141)
A flaw was discovered in the Linux kernel'
Red Hat
Kernel: tg3: buffer overflow in VPD firmware parsing
vendor_redhat·2013-03-27·CVSS 4.4
CVE-2013-1929 [MEDIUM] Kernel: tg3: buffer overflow in VPD firmware parsing
Kernel: tg3: buffer overflow in VPD firmware parsing
Heap-based buffer overflow in the tg3_read_vpd function in drivers/net/ethernet/broadcom/tg3.c in the Linux kernel before 3.8.6 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via crafted firmware that specifies a long string in the Vital Product Data (VPD) data structure.
Statement: This issue affects the versions of the Linux kernel as shipped with
Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
The Red Hat Security Response Team has rated this issue as having low security
impact because physical access is needed to exploit this issue. Future kernel
updates for Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2 may
address this issue. For additio
Debian
CVE-2013-1929: linux - Heap-based buffer overflow in the tg3_read_vpd function in drivers/net/ethernet/...
vendor_debian·2013·CVSS 4.4
CVE-2013-1929 [MEDIUM] CVE-2013-1929: linux - Heap-based buffer overflow in the tg3_read_vpd function in drivers/net/ethernet/...
Heap-based buffer overflow in the tg3_read_vpd function in drivers/net/ethernet/broadcom/tg3.c in the Linux kernel before 3.8.6 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via crafted firmware that specifies a long string in the Vital Product Data (VPD) data structure.
Scope: local
bookworm: resolved (fixed in 3.8.11-1)
bullseye: resolved (fixed in 3.8.11-1)
forky: resolved (fixed in 3.8.11-1)
sid: resolved (fixed in 3.8.11-1)
trixie: resolved (fixed in 3.8.11-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-7323 CVE-2014-1927 CVE-2014-1928 CVE-2014-1929 python-gnupg: incorrect fix against shell injection
bugzilla·2014-02-05·CVSS 7.5
CVE-2013-7323 [HIGH] CVE-2013-7323 CVE-2014-1927 CVE-2014-1928 CVE-2014-1929 python-gnupg: incorrect fix against shell injection
CVE-2013-7323 CVE-2014-1927 CVE-2014-1928 CVE-2014-1929 python-gnupg: incorrect fix against shell injection
It was found [1] that the fix for improved shell quoting to guard against shell injection, released in version 0.3.5 [2] of python-gnupg, is not sufficient.
This issue has been reported upstream [3].
[1] http://seclists.org/oss-sec/2014/q1/243
[2] https://code.google.com/p/python-gnupg/
[3] https://code.google.com/p/python-gnupg/issues/detail?id=98#c4
Discussion:
Created python-gnupg tracking bugs for this issue:
Affects: fedora-all [bug 1061600]
---
updates pushed to updates-testing for f19,f20,el6 (and built in rawhide)
---
This was assigned multiple CVE numbers:
CVE-2013-7323 Unrestricted use of unquoted strings in a shell,
within version 0.3.4
CVE-2014-1927 Erroneous
Bugzilla
CVE-2013-1929 Kernel: tg3: length overflow in VPD firmware parsing [fedora-all]
bugzilla·2013-04-09·CVSS 4.4
CVE-2013-1929 [MEDIUM] CVE-2013-1929 Kernel: tg3: length overflow in VPD firmware parsing [fedora-all]
CVE-2013-1929 Kernel: tg3: length overflow in VPD firmware parsing [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue a
Bugzilla
CVE-2013-1929 Kernel: tg3: buffer overflow in VPD firmware parsing
bugzilla·2013-04-09·CVSS 4.4
CVE-2013-1929 [MEDIUM] CVE-2013-1929 Kernel: tg3: buffer overflow in VPD firmware parsing
CVE-2013-1929 Kernel: tg3: buffer overflow in VPD firmware parsing
Linux kernel built with the Broadcom tg3 ethernet driver is vulnerable to a
buffer overflow. This could occur when the tg3 driver reads and copies firmware
string from hardware's product data(VPD), if it exceeds 32 characters.
A user with physical access to a machine could use this flaw to crash the
system or, potentially, escalate their privileges on the system.
Upstream fix:
-> https://git.kernel.org/linus/715230a44310a8cf66fbfb5a46f9a62a9b2de424
Reference:
-> http://openwall.com/lists/oss-security/2013/04/05/2
Discussion:
Statement:
This issue affects the versions of the Linux kernel as shipped with
Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
The Red Hat Security Response Team has rated this issue
arXiv
On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural Vulnerabilities
arxiv_fulltext·2024-01-20
On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural Vulnerabilities
On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural Vulnerabilities
Zhen Li
National Engineering Research Center for Big Data Technology and System, Services Computing Technology and System Lab, Hubei Key Laboratory of Distributed System Security, Hubei Engineering Research Center on Big Data Security, Cluster and Grid Computing Lab
JinYinHu Laboratory, Wuhan, China
School of Cyber Science and Engineering, Huazhong University of Science and Technology
Wuhan
China
[email protected]
Ning Wang
[1]
School of Cyber Science and Engineering, Huazhong University of Science and Technology
Wuhan
China
[email protected]
Deqing Zou
[1]
[2]
Corresponding author
School of Cyber Science and Engineering, Huazhong University of Science and Technology
Wuhan
China
d
http://cansecwest.com/slides/2013/PrivateCore%20CSW%202013.pdfhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=715230a44310a8cf66fbfb5a46f9a62a9b2de424http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101836.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00129.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1645.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.6http://www.mandriva.com/security/advisories?name=MDVSA-2013:176http://www.openwall.com/lists/oss-security/2013/04/06/3http://www.ubuntu.com/usn/USN-1834-1http://www.ubuntu.com/usn/USN-1835-1http://www.ubuntu.com/usn/USN-1836-1http://www.ubuntu.com/usn/USN-1838-1https://bugzilla.redhat.com/show_bug.cgi?id=949932https://github.com/torvalds/linux/commit/715230a44310a8cf66fbfb5a46f9a62a9b2de424http://cansecwest.com/slides/2013/PrivateCore%20CSW%202013.pdfhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=715230a44310a8cf66fbfb5a46f9a62a9b2de424http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101836.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00129.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1645.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.6http://www.mandriva.com/security/advisories?name=MDVSA-2013:176http://www.openwall.com/lists/oss-security/2013/04/06/3http://www.ubuntu.com/usn/USN-1834-1http://www.ubuntu.com/usn/USN-1835-1http://www.ubuntu.com/usn/USN-1836-1http://www.ubuntu.com/usn/USN-1838-1https://bugzilla.redhat.com/show_bug.cgi?id=949932https://github.com/torvalds/linux/commit/715230a44310a8cf66fbfb5a46f9a62a9b2de424
2013-06-07
Published