Vulnerability Name: | CVE-2013-2239 (CCN-85445) | ||||||||
Assigned: | 2013-07-05 | ||||||||
Published: | 2013-07-05 | ||||||||
Updated: | 2014-02-07 | ||||||||
Summary: | vzkernel before 042stab080.2 in the OpenVZ modification for the Linux kernel 2.6.32 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via (1) a crafted ploop driver ioctl call, related to the ploop_getdevice_ioc function in drivers/block/ploop/dev.c, or (2) a crafted quotactl system call, related to the compat_quotactl function in fs/quota/quota.c. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.7 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:N/A:N) 3.5 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:N/A:N/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-2239 Source: MLIST Type: UNKNOWN [oss-security] 20130704 OpenVZ security repport - Multiple memory leaks (CVE-2013-2239) Source: CCN Type: OpenVZ Web site OpenVZ Source: CONFIRM Type: UNKNOWN http://wiki.openvz.org/Download/kernel/rhel6-testing/042stab080.2 Source: DEBIAN Type: UNKNOWN DSA-2766 Source: DEBIAN Type: DSA-2766 linux-2.6 -- privilege escalation/denial of service/information leak Source: CCN Type: BID-60977 OpenVZ Kernel Memory Leak Multiple Local Information Disclosure Vulnerabilities Source: CONFIRM Type: UNKNOWN https://bugs.gentoo.org/show_bug.cgi?id=475762 Source: XF Type: UNKNOWN openvzkernel-cve20132239-info-disclosure(85445) Source: CCN Type: Packet Storm Security [7-05-2013] OpenVZ Kernel 2.6.32 Memory Leaks Source: CONFIRM Type: UNKNOWN https://security-tracker.debian.org/tracker/CVE-2013-2239 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |