cbcvebase.
CVE-2013-1929
published 2013-06-07

CVE-2013-1929: Heap-based buffer overflow in the tg3_read_vpd function in drivers/net/ethernet/broadcom/tg3.c in the Linux kernel before 3.8.6 allows physically proximate…

PriorityP424medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.72%
50.2th percentile
Heap-based buffer overflow in the tg3_read_vpd function in drivers/net/ethernet/broadcom/tg3.c in the Linux kernel before 3.8.6 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via crafted firmware that specifies a long string in the Vital Product Data (VPD) data structure.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.8.11-1 (bookworm)linux 3.8.11-1 (bookworm)
linuxlinux_kernel<= 3.8.5
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 3.8.11-13.8.11-1
linuxlinux_kernel>= 0 < 3.8.11-13.8.11-1
linuxlinux_kernel>= 0 < 3.8.11-13.8.11-1
linuxlinux_kernel>= 0 < 3.8.11-13.8.11-1
python-gnupg_projectpython-gnupg>= 0.3.5 < 0.3.70.3.7

CVSS provenance

nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
ghsa7.5HIGH
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
vendor_ubuntu4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.