CVE-2013-3076

CVSS v2.0 4.9 (Medium)
49% Progress
EPSS 0.04 % (5th)
0.04% Progress
Affected Products 1
Advisories 29

The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call, related to the hash_recvmsg function in crypto/algif_hash.c and the skcipher_recvmsg function in crypto/algif_skcipher.c.

Weaknesses
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2013-04-22 11:40:59
(11 years ago)
Updated Date
2017-11-29 02:29:04
(6 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel Rc7 3.9 and prior versions cpe:2.3:o:linux:linux_kernel::rc7 <= 3.9
  Linux Kernel 3.9 Rc1 cpe:2.3:o:linux:linux_kernel:3.9:rc1
  Linux Kernel 3.9 Rc2 cpe:2.3:o:linux:linux_kernel:3.9:rc2
  Linux Kernel 3.9 Rc3 cpe:2.3:o:linux:linux_kernel:3.9:rc3
  Linux Kernel 3.9 Rc4 cpe:2.3:o:linux:linux_kernel:3.9:rc4
  Linux Kernel 3.9 Rc5 cpe:2.3:o:linux:linux_kernel:3.9:rc5
  Linux Kernel 3.9 Rc6 cpe:2.3:o:linux:linux_kernel:3.9:rc6
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...