Vulnerability Name:

CVE-2013-1773 (CCN-82454)

Assigned:2012-12-09
Published:2012-12-09
Updated:2023-02-13
Summary:Buffer overflow in the VFAT filesystem implementation in the Linux kernel before 3.3 allows local users to gain privileges or cause a denial of service (system crash) via a VFAT write operation on a filesystem with the utf8 mount option, which is not properly handled during UTF-8 to UTF-16 conversion.
CVSS v3 Severity:5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:6.2 Medium (CVSS v2 Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C)
4.9 Medium (Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
4.4 Medium (CCN CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P)
3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.2 Medium (REDHAT CVSS v2 Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C)
4.9 Medium (REDHAT Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2013-1773

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: RHSA-2013-0566
Important: kernel-rt security and bug fix update

Source: CCN
Type: RHSA-2013-0744
Important: kernel security and bug fix update

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: RHSA-2013-0928
Important: kernel security and bug fix update

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: RHSA-2013-1026
Important: kernel security and bug fix update

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: DEBIAN
Type: DSA-2668
linux-2.6 -- privilege escalation/denial of service/information leak

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: OSVDB ID: 88310
Google Android Kernel Filename Write Handling Local DoS

Source: CCN
Type: BID-58200
Linux Kernel VFAT Filesystem Local Buffer Overflow Vulnerability

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: Red Hat Bugzilla Bug 916115
CVE-2013-1773 kernel: VFAT slab-based buffer overflow

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: XF
Type: UNKNOWN
kernel-vfat-bo(82454)

Source: CCN
Type: Linux Kernel GIT Repository
NLS: improve UTF8 -> UTF16 string conversion routine

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:6:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:6::client:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:6::computenode:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:6::server:*:*:*:*:*
  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:6::workstation:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:linux:linux_kernel:3.0.1:*:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:3.0.4:*:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:3.0.5:*:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:3.1.8:*:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:3.2.1:*:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:3.2.9:*:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:3.3.2:*:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:3.3.4:*:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:3.0.2:*:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:3.2.13:*:*:*:*:*:*:*
  • AND
  • cpe:/o:redhat:enterprise_linux:6:*:server:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:6:*:workstation:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_hpc_node:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_mrg:2.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20131773
    V
    CVE-2013-1773
    2022-05-20
    oval:org.opensuse.security:def:33117
    P
    Security update for openexr (Important)
    2022-01-12
    oval:org.opensuse.security:def:33068
    P
    Security update for libvpx (Moderate)
    2021-12-23
    oval:org.opensuse.security:def:33011
    P
    Security update for hivex (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:33900
    P
    Security update for java-1_7_0-openjdk (Moderate)
    2021-04-29
    oval:org.opensuse.security:def:32404
    P
    Security update for w3m (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29848
    P
    Security update for Linux kernel
    2020-12-01
    oval:org.opensuse.security:def:33156
    P
    libjasper on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28971
    P
    Security update for postgresql94 (Important)
    2020-12-01
    oval:org.opensuse.security:def:32617
    P
    xorg-x11 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28383
    P
    Security update for rubygem-activesupport-3_2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33223
    P
    pam_ldap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29074
    P
    Security update for cups (Important)
    2020-12-01
    oval:org.opensuse.security:def:32768
    P
    perl-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28462
    P
    Security update for xorg-x11-libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29130
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:28678
    P
    Security update for MozillaFirefox, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:32393
    P
    Security update for tomcat6 (Important)
    2020-12-01
    oval:org.opensuse.security:def:29812
    P
    Security update for jasper
    2020-12-01
    oval:org.opensuse.security:def:28819
    P
    Security update for python
    2020-12-01
    oval:org.opensuse.security:def:32482
    P
    NetworkManager-gnome on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28382
    P
    Security update for rubygem-activerecord-3_2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33179
    P
    libsamplerate on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29025
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:32711
    P
    libfreebl3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28394
    P
    Security update for samba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33861
    P
    Security update for jakarta-commons-fileupload (Important)
    2020-12-01
    oval:org.opensuse.security:def:29113
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:32855
    P
    evince on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28593
    P
    Security update for openvpn
    2020-12-01
    oval:org.opensuse.security:def:32392
    P
    Security update for tomcat6 (Important)
    2020-12-01
    oval:org.opensuse.security:def:29174
    P
    Security update to ucode-intel (Important)
    2020-12-01
    oval:org.opensuse.security:def:28735
    P
    Security update for kvm and libvirt
    2020-12-01
    oval:org.mitre.oval:def:24665
    P
    SUSE-SU-2014:0287-1 -- Security update for Linux kernel
    2015-03-16
    oval:org.mitre.oval:def:27102
    P
    ELSA-2013-2513 -- Unbreakable Enterprise kernel security and bugfix update (important)
    2014-12-15
    oval:org.mitre.oval:def:18245
    P
    USN-1778-1 -- linux-ti-omap4 vulnerabilities
    2014-06-30
    oval:org.mitre.oval:def:17380
    P
    USN-1776-1 -- linux-ec2 vulnerabilities
    2014-06-30
    oval:org.mitre.oval:def:18253
    P
    USN-1760-1 -- linux-lts-backport-oneiric vulnerabilities
    2014-06-30
    oval:org.mitre.oval:def:18028
    P
    USN-1756-1 -- linux vulnerabilities
    2014-06-30
    oval:org.mitre.oval:def:18139
    P
    USN-1775-1 -- linux vulnerabilities
    2014-06-30
    oval:org.mitre.oval:def:19799
    P
    DSA-2668-1 linux-2.6 - several
    2014-06-23
    oval:org.mitre.oval:def:23777
    P
    ELSA-2013:0744: kernel security and bug fix update (Important)
    2014-05-26
    oval:org.mitre.oval:def:20990
    P
    RHSA-2013:0744: kernel security and bug fix update (Important)
    2014-02-17
    oval:com.redhat.rhsa:def:20130744
    P
    RHSA-2013:0744: kernel security and bug fix update (Important)
    2013-04-23
    oval:com.ubuntu.xenial:def:201317730000000
    V
    CVE-2013-1773 on Ubuntu 16.04 LTS (xenial) - medium.
    2013-02-28
    oval:com.ubuntu.precise:def:20131773000
    V
    CVE-2013-1773 on Ubuntu 12.04 LTS (precise) - medium.
    2013-02-28
    oval:com.ubuntu.trusty:def:20131773000
    V
    CVE-2013-1773 on Ubuntu 14.04 LTS (trusty) - medium.
    2013-02-28
    oval:com.ubuntu.xenial:def:20131773000
    V
    CVE-2013-1773 on Ubuntu 16.04 LTS (xenial) - medium.
    2013-02-28
    BACK
    linux linux kernel 3.0.1
    linux linux kernel 3.0.4
    linux linux kernel 3.0.5
    linux linux kernel 3.1.8
    linux linux kernel 3.2.1
    linux linux kernel 3.2.9
    linux linux kernel 3.3.2
    linux linux kernel 3.3.4
    linux linux kernel 3.0.2
    linux linux kernel 3.2.13
    redhat enterprise linux 6
    redhat enterprise linux 6
    redhat enterprise linux desktop 6
    redhat enterprise linux hpc node 6
    redhat enterprise mrg 2.0