CVE-2013-4343

CVSS v2.0 6.9 (Medium)
69% Progress
EPSS 0.04 % (5th)
0.04% Progress
Affected Products 2
Advisories 37

Use-after-free vulnerability in drivers/net/tun.c in the Linux kernel through 3.11.1 allows local users to gain privileges by leveraging the CAP_NET_ADMIN capability and providing an invalid tuntap interface name in a TUNSETIFF ioctl call.

Weaknesses
CWE-399
Resource Management Errors
Related CVEs
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2013-09-25 10:31:29
(11 years ago)
Updated Date
2023-08-11 18:13:04
(13 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 3.8 version and prior 3.10.16 version cpe:2.3:o:linux:linux_kernel >= 3.8 < 3.10.16
  Linux Kernel from 3.11 version and prior 3.11.5 version cpe:2.3:o:linux:linux_kernel >= 3.11 < 3.11.5

Configuration #2

    CPE23 From Up To
  Canonical Ubuntu Linux 13.04 cpe:2.3:o:canonical:ubuntu_linux:13.04
  Canonical Ubuntu Linux 13.10 cpe:2.3:o:canonical:ubuntu_linux:13.10
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...