|
|
| |
|
| |
kernel: multiple vulnerabilities
| Package(s): | kernel |
CVE #(s): | CVE-2013-1059
CVE-2013-2234
|
| Created: | July 8, 2013 |
Updated: | August 20, 2013 |
| Description: |
From the Red Hat bugzilla [1, 2]:
Linux kernel built with the IPSec key_socket support(CONFIG_NET_KEY=m) is
vulnerable to an information leakage flaw. It occurs while using key_socket's
notify interface.
A user/program able to access the PF_KEY key_sockets could use this flaw to
leak kernel memory bytes. (CVE-2013-2234)
Linux kernel built with the Ceph core library(CONFIG_CEPH_LIB) support is
vulnerable to a NULL pointer dereference flaw. It could occur while handling
auth_reply messages from a CEPH client.
A remote user/program could use this flaw to crash the system, resulting in
denial of service. (CVE-2013-1059) |
| Alerts: |
|
( Log in to post comments)
|
|
|