UBUNTU-CVE-2013-6432
Dashboard / Vulnerabilities / UBUNTU-CVE-2013-6432
UBUNTU-CVE-2013-6432
Summary:
Details: The ping_recvmsg function in net/ipv4/ping.c in the Linux kernel before 3.12.4 does not properly interact with read system calls on ping sockets, which allows local users to cause a denial of service (NULL pointer dereference and system crash) by leveraging unspecified privileges to execute a crafted application.
References: https://ubuntu.com/security/CVE-2013-6432, http://www.openwall.com/lists/oss-security/2013/12/06/2, https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cf970c002d270c36202bd5b9c2804d3097a52da0, https://ubuntu.com/security/notices/USN-2113-1, https://ubuntu.com/security/notices/USN-2117-1, https://www.cve.org/CVERecord?id=CVE-2013-6432
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
