[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-6368Date: (C)2013-12-19   (M)2024-04-11


The KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges or cause a denial of service (system crash) via a VAPIC synchronization operation involving a page-end address.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.2
Exploit Score: 1.9
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: HIGH
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
BID-64291
RHSA-2013:1801
RHSA-2014:0163
RHSA-2014:0284
USN-2113-1
USN-2117-1
USN-2133-1
USN-2134-1
USN-2135-1
USN-2136-1
USN-2138-1
USN-2139-1
USN-2141-1
http://www.openwall.com/lists/oss-security/2013/12/12/12
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fda4e2e85589191b123d31cdc21fd33ee70f50fd
https://bugzilla.redhat.com/show_bug.cgi?id=1032210
https://github.com/torvalds/linux/commit/fda4e2e85589191b123d31cdc21fd33ee70f50fd
openSUSE-SU-2014:0204
openSUSE-SU-2014:0205
openSUSE-SU-2014:0247

CWE    1
CWE-20
OVAL    69
oval:org.secpod.oval:def:106503
oval:org.secpod.oval:def:106823
oval:org.secpod.oval:def:701575
oval:org.secpod.oval:def:106468
...

© SecPod Technologies