The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 does not initialize certain structure members, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-2489 | The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 does not initialize certain structure members, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability. |
Ubuntu USN |
USN-1793-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-1794-1 | Linux kernel (OMAP4) vulnerabilities |
Ubuntu USN |
USN-1795-1 | Linux kernel (Quantal HWE) vulnerabilities |
Ubuntu USN |
USN-1796-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-1797-1 | Linux kernel (OMAP4) vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T15:44:32.059Z
Reserved: 2013-03-08T00:00:00
Link: CVE-2013-2547
No data.
Status : Deferred
Published: 2013-03-15T20:55:08.633
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-2547
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN