CVE-2013-6432
published 2013-12-09CVE-2013-6432: The ping_recvmsg function in net/ipv4/ping.c in the Linux kernel before 3.12.4 does not properly interact with read system calls on ping sockets, which allows…
PriorityP413medium4.6CVSS 2.0
AVLACLAuSCNINAC
EPSS
0.47%
38.9th percentile
The ping_recvmsg function in net/ipv4/ping.c in the Linux kernel before 3.12.4 does not properly interact with read system calls on ping sockets, which allows local users to cause a denial of service (NULL pointer dereference and system crash) by leveraging unspecified privileges to execute a crafted application.
Affected
253 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.12.6-1 (bookworm) | linux 3.12.6-1 (bookworm) |
| linux | linux_kernel | <= 3.12.3 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:S/C:N/I:N/A:C
osv4.6MEDIUM
vendor_ubuntu7.1HIGH
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Saucy HWE) vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 7.1
CVE-2013-4563 [HIGH] Linux kernel (Saucy HWE) vulnerabilities
Title: Linux kernel (Saucy HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Saran Neti reported a flaw in the ipv6 UDP Fragmentation Offload (UFI) in
the Linux kernel. A remote attacker could exploit this flaw to cause a
denial of service (panic). (CVE-2013-4563)
Mathy Vanhoef discovered an error in the the way the ath9k driver was
handling the BSSID masking. A remote attacker could exploit this error to
discover the original MAC address after a spoofing atack. (CVE-2013-4579)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsystem. A local user could
exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)
Andrew Honig reported a flaw in the apic_get_tmcct functi
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 7.1
CVE-2013-4563 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Saran Neti reported a flaw in the ipv6 UDP Fragmentation Offload (UFI) in
the Linux kernel. A remote attacker could exploit this flaw to cause a
denial of service (panic). (CVE-2013-4563)
Mathy Vanhoef discovered an error in the the way the ath9k driver was
handling the BSSID masking. A remote attacker could exploit this error to
discover the original MAC address after a spoofing atack. (CVE-2013-4579)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsystem. A local user could
exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)
Andrew Honig reported a flaw in the apic_get_tmcct function of the Ke
Red Hat
Kernel: ping: NULL pointer dereference on write to msg_name
vendor_redhat·2013-11-18·CVSS 4.6
CVE-2013-6432 [MEDIUM] CWE-476 Kernel: ping: NULL pointer dereference on write to msg_name
Kernel: ping: NULL pointer dereference on write to msg_name
The ping_recvmsg function in net/ipv4/ping.c in the Linux kernel before 3.12.4 does not properly interact with read system calls on ping sockets, which allows local users to cause a denial of service (NULL pointer dereference and system crash) by leveraging unspecified privileges to execute a crafted application.
Statement: This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2013-6432: linux - The ping_recvmsg function in net/ipv4/ping.c in the Linux kernel before 3.12.4 d...
vendor_debian·2013·CVSS 4.6
CVE-2013-6432 [MEDIUM] CVE-2013-6432: linux - The ping_recvmsg function in net/ipv4/ping.c in the Linux kernel before 3.12.4 d...
The ping_recvmsg function in net/ipv4/ping.c in the Linux kernel before 3.12.4 does not properly interact with read system calls on ping sockets, which allows local users to cause a denial of service (NULL pointer dereference and system crash) by leveraging unspecified privileges to execute a crafted application.
Scope: local
bookworm: resolved (fixed in 3.12.6-1)
bullseye: resolved (fixed in 3.12.6-1)
forky: resolved (fixed in 3.12.6-1)
sid: resolved (fixed in 3.12.6-1)
trixie: resolved (fixed in 3.12.6-1)
GHSA
GHSA-fw6g-56pg-38xh: The ping_recvmsg function in net/ipv4/ping
ghsa_unreviewed·2022-05-17
CVE-2013-6432 [MEDIUM] GHSA-fw6g-56pg-38xh: The ping_recvmsg function in net/ipv4/ping
The ping_recvmsg function in net/ipv4/ping.c in the Linux kernel before 3.12.4 does not properly interact with read system calls on ping sockets, which allows local users to cause a denial of service (NULL pointer dereference and system crash) by leveraging unspecified privileges to execute a crafted application.
OSV
CVE-2013-6432: The ping_recvmsg function in net/ipv4/ping
osv·2013-12-09·CVSS 4.6
CVE-2013-6432 [MEDIUM] CVE-2013-6432: The ping_recvmsg function in net/ipv4/ping
The ping_recvmsg function in net/ipv4/ping.c in the Linux kernel before 3.12.4 does not properly interact with read system calls on ping sockets, which allows local users to cause a denial of service (NULL pointer dereference and system crash) by leveraging unspecified privileges to execute a crafted application.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=cf970c002d270c36202bd5b9c2804d3097a52da0http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00003.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.12.4http://www.openwall.com/lists/oss-security/2013/12/06/6http://www.ubuntu.com/usn/USN-2113-1http://www.ubuntu.com/usn/USN-2117-1https://bugzilla.redhat.com/show_bug.cgi?id=1039046https://github.com/torvalds/linux/commit/cf970c002d270c36202bd5b9c2804d3097a52da0http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=cf970c002d270c36202bd5b9c2804d3097a52da0http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00003.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.12.4http://www.openwall.com/lists/oss-security/2013/12/06/6http://www.ubuntu.com/usn/USN-2113-1http://www.ubuntu.com/usn/USN-2117-1https://bugzilla.redhat.com/show_bug.cgi?id=1039046https://github.com/torvalds/linux/commit/cf970c002d270c36202bd5b9c2804d3097a52da0
2013-12-09
Published