CVE-2013-3225

CVSS v2.0 4.9 (Medium)
49% Progress
EPSS 0.04 % (5th)
0.04% Progress
Affected Products 1
Advisories 36

The rfcomm_sock_recvmsg function in net/bluetooth/rfcomm/sock.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.

Weaknesses
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2013-04-22 11:41:01
(11 years ago)
Updated Date
2023-11-07 02:15:54
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel Rc6 3.9 and prior versions cpe:2.3:o:linux:linux_kernel::rc6 <= 3.9
  Linux Kernel 3.9 Rc1 cpe:2.3:o:linux:linux_kernel:3.9:rc1
  Linux Kernel 3.9 Rc2 cpe:2.3:o:linux:linux_kernel:3.9:rc2
  Linux Kernel 3.9 Rc3 cpe:2.3:o:linux:linux_kernel:3.9:rc3
  Linux Kernel 3.9 Rc4 cpe:2.3:o:linux:linux_kernel:3.9:rc4
  Linux Kernel 3.9 Rc5 cpe:2.3:o:linux:linux_kernel:3.9:rc5
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...