CVE-2013-4513
published 2013-11-12CVE-2013-4513: Buffer overflow in the oz_cdev_write function in drivers/staging/ozwpan/ozcdev.c in the Linux kernel before 3.12 allows local users to cause a denial of…
PriorityP419medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.51%
40.6th percentile
Buffer overflow in the oz_cdev_write function in drivers/staging/ozwpan/ozcdev.c in the Linux kernel before 3.12 allows local users to cause a denial of service or possibly have unspecified other impact via a crafted write operation.
Affected
242 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.12-1 (bookworm) | linux 3.12-1 (bookworm) |
| linux | linux_kernel | <= 3.11.7 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_ubuntu6.9MEDIUM
vendor_debian4.9LOW
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 6.9
CVE-2013-4470 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Hannes Frederic Sowa discovered a flaw in the Linux kernel's UDP
Fragmentation Offload (UFO). An unprivileged local user could exploit this
flaw to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2013-4470)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo
Devices USB over WiFi devices. A local user could exploit this flaw to
cause a denial of service or possibly unspecified impact. (CVE-2013-4513)
Nico Golde and Fabian Y
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 6.9
CVE-2013-4470 [MEDIUM] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Hannes Frederic Sowa discovered a flaw in the Linux kernel's UDP
Fragmentation Offload (UFO). An unprivileged local user could exploit this
flaw to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2013-4470)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo
Devices USB over WiFi devices. A local user could exploit this flaw to
cause a denial of service or possibly unspecified impact. (CVE-2013-4513)
Nico Golde
Ubuntu
Linux kernel (Saucy HWE) vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel (Saucy HWE) vulnerabilities
Title: Linux kernel (Saucy HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Jason Wang discovered a bug in t
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 3.6
CVE-2013-2930 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian Yamaguch
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Jason Wang discovered a bug in the network f
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 3.6
CVE-2013-2930 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 3.6
CVE-2013-2930 [LOW] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Jason Wang discovered a bug in the network flow dissector in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (infinite loop). (CVE-2013-4348)
Multiple integer overflow flaws were discover
Red Hat
Kernel: staging: ozwpan: buffer overflow in oz_cdev_write
vendor_redhat·2013-11-22·CVSS 4.9
CVE-2013-4513 [MEDIUM] Kernel: staging: ozwpan: buffer overflow in oz_cdev_write
Kernel: staging: ozwpan: buffer overflow in oz_cdev_write
Buffer overflow in the oz_cdev_write function in drivers/staging/ozwpan/ozcdev.c in the Linux kernel before 3.12 allows local users to cause a denial of service or possibly have unspecified other impact via a crafted write operation.
Statement: This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2013-4513: linux - Buffer overflow in the oz_cdev_write function in drivers/staging/ozwpan/ozcdev.c...
vendor_debian·2013·CVSS 4.9
CVE-2013-4513 [MEDIUM] CVE-2013-4513: linux - Buffer overflow in the oz_cdev_write function in drivers/staging/ozwpan/ozcdev.c...
Buffer overflow in the oz_cdev_write function in drivers/staging/ozwpan/ozcdev.c in the Linux kernel before 3.12 allows local users to cause a denial of service or possibly have unspecified other impact via a crafted write operation.
Scope: local
bookworm: resolved (fixed in 3.12-1)
bullseye: resolved (fixed in 3.12-1)
forky: resolved (fixed in 3.12-1)
sid: resolved (fixed in 3.12-1)
trixie: resolved (fixed in 3.12-1)
GHSA
GHSA-6wc6-7j53-rh84: Buffer overflow in the oz_cdev_write function in drivers/staging/ozwpan/ozcdev
ghsa_unreviewed·2022-05-17
CVE-2013-4513 [MEDIUM] CWE-119 GHSA-6wc6-7j53-rh84: Buffer overflow in the oz_cdev_write function in drivers/staging/ozwpan/ozcdev
Buffer overflow in the oz_cdev_write function in drivers/staging/ozwpan/ozcdev.c in the Linux kernel before 3.12 allows local users to cause a denial of service or possibly have unspecified other impact via a crafted write operation.
OSV
CVE-2013-4513: Buffer overflow in the oz_cdev_write function in drivers/staging/ozwpan/ozcdev
osv·2013-11-12·CVSS 4.9
CVE-2013-4513 [MEDIUM] CVE-2013-4513: Buffer overflow in the oz_cdev_write function in drivers/staging/ozwpan/ozcdev
Buffer overflow in the oz_cdev_write function in drivers/staging/ozwpan/ozcdev.c in the Linux kernel before 3.12 allows local users to cause a denial of service or possibly have unspecified other impact via a crafted write operation.
No detection rules found.
Bugzilla
CVE-2012-5629 JBoss: allows empty password to authenticate against LDAP
bugzilla·2012-12-10·CVSS 7.5
CVE-2012-5629 [HIGH] CVE-2012-5629 JBoss: allows empty password to authenticate against LDAP
CVE-2012-5629 JBoss: allows empty password to authenticate against LDAP
The jboss-as-domain-management and jbosssx (now part of PicketLink) modules under default conditions allow users to authenticate with a blank password when LDAP authentication is configured and unauthenticated authentication is supported by the LDAP server. This is in violation of the recommendations of RFC 4513, which states that clients should disallow empty passwords as input to a name/password authentication interface, and not allow the input of an empty password to trigger the selection of the unauthenticated authentication mechanism.
Discussion:
This issue has been addressed in following products:
JBEWP 5 for RHEL 4
JBEWP 5 for RHEL 5
JBEWP 5 for RHEL 6
Via RHSA-2013:0230 https://rhn.redhat.com/errata/RHSA-2
Bugzilla
CVE kernel non-issue statements
bugzilla·2010-05-13·CVSS 5.0
[MEDIUM] CVE kernel non-issue statements
CVE kernel non-issue statements
This bug is to collect statements for Linux kernel-related CVE's that do not have their own top-level CVE SRT bug because it did not affect any of our supported kernels. These statements were also referred to as NVD statements and are noted on the NVD web site.
(From bug 589808) Do not change the bug alias, it needs to have "CVE" in the title. You can add extra statements in new comments or editing existing comments and they will be picked up correctly.
Discussion:
Statement CVE-2010-0747:
Not vulnerable. This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, 5 and Red Hat Enterprise MRG as they did not backport an out-of-tree drbd module (drbd8).
Statement CVE-2010-1446:
Not vulnerable. This issue di
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c2c65cd2e14ada6de44cb527e7f1990bede24e15http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.htmlhttp://www.openwall.com/lists/oss-security/2013/11/04/22http://www.securityfocus.com/bid/63508http://www.ubuntu.com/usn/USN-2068-1http://www.ubuntu.com/usn/USN-2069-1http://www.ubuntu.com/usn/USN-2070-1http://www.ubuntu.com/usn/USN-2071-1http://www.ubuntu.com/usn/USN-2072-1http://www.ubuntu.com/usn/USN-2073-1http://www.ubuntu.com/usn/USN-2074-1http://www.ubuntu.com/usn/USN-2075-1http://www.ubuntu.com/usn/USN-2076-1https://github.com/torvalds/linux/commit/c2c65cd2e14ada6de44cb527e7f1990bede24e15https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.12.bz2http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c2c65cd2e14ada6de44cb527e7f1990bede24e15http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.htmlhttp://www.openwall.com/lists/oss-security/2013/11/04/22http://www.securityfocus.com/bid/63508http://www.ubuntu.com/usn/USN-2068-1http://www.ubuntu.com/usn/USN-2069-1http://www.ubuntu.com/usn/USN-2070-1http://www.ubuntu.com/usn/USN-2071-1http://www.ubuntu.com/usn/USN-2072-1http://www.ubuntu.com/usn/USN-2073-1http://www.ubuntu.com/usn/USN-2074-1http://www.ubuntu.com/usn/USN-2075-1http://www.ubuntu.com/usn/USN-2076-1https://github.com/torvalds/linux/commit/c2c65cd2e14ada6de44cb527e7f1990bede24e15https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.12.bz2
2013-11-12
Published