[Forgot Password]
Login  Register Subscribe

24547

 
 

132803

 
 

128796

 
 

909

 
 

106110

 
 

152

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML view JSON

CVE-2013-6368Date: (C)2013-12-19   (M)2019-08-09


The KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges or cause a denial of service (system crash) via a VAPIC synchronization operation involving a page-end address.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.2
Exploit Score: 1.9
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: HIGH
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
BID-64291
RHSA-2013:1801
RHSA-2014:0163
RHSA-2014:0284
USN-2113-1
USN-2117-1
USN-2133-1
USN-2134-1
USN-2135-1
USN-2136-1
USN-2138-1
USN-2139-1
USN-2141-1
http://www.openwall.com/lists/oss-security/2013/12/12/12
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=fda4e2e85589191b123d31cdc21fd33ee70f50fd
https://bugzilla.redhat.com/show_bug.cgi?id=1032210
https://github.com/torvalds/linux/commit/fda4e2e85589191b123d31cdc21fd33ee70f50fd
openSUSE-SU-2014:0204
openSUSE-SU-2014:0205
openSUSE-SU-2014:0247

CPE    279
cpe:/o:redhat:enterprise_linux:6
cpe:/o:linux:linux_kernel:3.0.40
cpe:/o:linux:linux_kernel:3.1.10
cpe:/o:linux:linux_kernel:3.0.42
...
CWE    1
CWE-20
OVAL    70
oval:org.secpod.oval:def:106503
oval:org.secpod.oval:def:106980
oval:org.secpod.oval:def:106970
oval:org.secpod.oval:def:106971
...

© SecPod Technologies