UBUNTU-CVE-2013-2852
Dashboard / Vulnerabilities / UBUNTU-CVE-2013-2852
UBUNTU-CVE-2013-2852
Summary:
Details: Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including format string specifiers in an fwpostfix modprobe parameter, leading to improper construction of an error message.
References: https://ubuntu.com/security/CVE-2013-2852, https://bugzilla.redhat.com/show_bug.cgi?id=969518, http://www.openwall.com/lists/oss-security/2013/06/06/13, http://git.kernel.org/cgit/linux/kernel/git/linville/wireless.git/commit/?id=9538cbaab6e8b8046039b4b2eb6c9d614dc782bd, https://ubuntu.com/security/notices/USN-1899-1, https://ubuntu.com/security/notices/USN-1900-1, https://ubuntu.com/security/notices/USN-1918-1, https://ubuntu.com/security/notices/USN-1919-1, https://ubuntu.com/security/notices/USN-1915-1, https://ubuntu.com/security/notices/USN-1916-1, https://ubuntu.com/security/notices/USN-1914-1, https://ubuntu.com/security/notices/USN-1917-1, https://ubuntu.com/security/notices/USN-1920-1, https://ubuntu.com/security/notices/USN-1930-1, https://ubuntu.com/security/notices/USN-1936-1, https://www.cve.org/CVERecord?id=CVE-2013-2852
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
