CVE-2013-1059
HIGH severity · CVSS 7.8 · CWE-476
7.8CVSS HIGH
Summary
net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an auth_reply message that triggers an attempted build_request operation.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impactNone
Availability impact—
Exploit probability (EPSS)5%
AV:N/AC:L/Au:N/C:N/I:N/A:C
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://hkpco.kr/advisory/CVE-2013-1059.txtAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00012.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.htmlAdvisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00129.htmlAdvisory
- http://www.openwall.com/lists/oss-security/2013/07/09/7Advisory
- http://www.ubuntu.com/usn/USN-1941-1Advisory
- http://www.ubuntu.com/usn/USN-1942-1Advisory