CVE-2013-4588
published 2013-11-20CVE-2013-4588: Multiple stack-based buffer overflows in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 2.6.33, when CONFIG_IP_VS is used, allow local users to gain…
PriorityP433high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.40%
32.6th percentile
Multiple stack-based buffer overflows in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 2.6.33, when CONFIG_IP_VS is used, allow local users to gain privileges by leveraging the CAP_NET_ADMIN capability for (1) a getsockopt system call, related to the do_ip_vs_get_ctl function, or (2) a setsockopt system call, related to the do_ip_vs_set_ctl function.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | linux | — | — |
| linux | linux_kernel | < 2.6.33 | 2.6.33 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_debian7.0LOW
vendor_redhat7.0HIGH
vendor_ubuntu5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h3c6-f59r-9hjh: Multiple stack-based buffer overflows in net/netfilter/ipvs/ip_vs_ctl
ghsa_unreviewed·2022-05-13
CVE-2013-4588 [HIGH] CWE-119 GHSA-h3c6-f59r-9hjh: Multiple stack-based buffer overflows in net/netfilter/ipvs/ip_vs_ctl
Multiple stack-based buffer overflows in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 2.6.33, when CONFIG_IP_VS is used, allow local users to gain privileges by leveraging the CAP_NET_ADMIN capability for (1) a getsockopt system call, related to the do_ip_vs_get_ctl function, or (2) a setsockopt system call, related to the do_ip_vs_set_ctl function.
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 5.8
CVE-2013-4345 [MEDIUM] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
A flaw was discovered in the Linux kernel's IP Virtual Server (IP_VS)
support. A local user with the CAP_NET_ADMIN capability could exploit this
flaw to gain additional administrative privileges. (CVE-2013-4588)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
debugfs filesystem. An administrative local user could exploit this flaw to
cause a denial of service (OOPS). (CVE-2013-6378)
Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 5.8
CVE-2013-4345 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
A flaw was discovered in the Linux kernel's IP Virtual Server (IP_VS)
support. A local user with the CAP_NET_ADMIN capability could exploit this
flaw to gain additional administrative privileges. (CVE-2013-4588)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
debugfs filesystem. An administrative local user could exploit this flaw to
cause a denial of service (OOPS). (CVE-2013-6378)
Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploi
Red Hat
Kernel: net: ipvs: stack buffer overflow
vendor_redhat·2013-11-11·CVSS 7.0
CVE-2013-4588 [HIGH] CWE-121 Kernel: net: ipvs: stack buffer overflow
Kernel: net: ipvs: stack buffer overflow
Multiple stack-based buffer overflows in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 2.6.33, when CONFIG_IP_VS is used, allow local users to gain privileges by leveraging the CAP_NET_ADMIN capability for (1) a getsockopt system call, related to the do_ip_vs_get_ctl function, or (2) a setsockopt system call, related to the do_ip_vs_set_ctl function.
Statement: The Red Hat Security Response Team does not consider this issue to be a security flaw.
Please see http://seclists.org/oss-sec/2014/q1/174 for CVE REJECT request and further information.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: ke
Debian
CVE-2013-4588: linux - Multiple stack-based buffer overflows in net/netfilter/ipvs/ip_vs_ctl.c in the L...
vendor_debian·2013·CVSS 7.0
CVE-2013-4588 [HIGH] CVE-2013-4588: linux - Multiple stack-based buffer overflows in net/netfilter/ipvs/ip_vs_ctl.c in the L...
Multiple stack-based buffer overflows in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 2.6.33, when CONFIG_IP_VS is used, allow local users to gain privileges by leveraging the CAP_NET_ADMIN capability for (1) a getsockopt system call, related to the do_ip_vs_get_ctl function, or (2) a setsockopt system call, related to the do_ip_vs_set_ctl function.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
http://ftp.linux.org.uk/pub/linux/linux-2.6/ChangeLog-2.6.33http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=04bcef2a83f40c6db24222b27a52892cba39dffbhttp://www.openwall.com/lists/oss-security/2013/11/15/12http://www.securityfocus.com/bid/63744http://www.ubuntu.com/usn/USN-2064-1http://www.ubuntu.com/usn/USN-2065-1https://bugzilla.redhat.com/show_bug.cgi?id=1030800https://github.com/torvalds/linux/commit/04bcef2a83f40c6db24222b27a52892cba39dffbhttp://ftp.linux.org.uk/pub/linux/linux-2.6/ChangeLog-2.6.33http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=04bcef2a83f40c6db24222b27a52892cba39dffbhttp://www.openwall.com/lists/oss-security/2013/11/15/12http://www.securityfocus.com/bid/63744http://www.ubuntu.com/usn/USN-2064-1http://www.ubuntu.com/usn/USN-2065-1https://bugzilla.redhat.com/show_bug.cgi?id=1030800https://github.com/torvalds/linux/commit/04bcef2a83f40c6db24222b27a52892cba39dffb
2013-11-20
Published