7.2

CVE-2013-3301

Exploit

The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then making an lseek system call.

Data is provided by the National Vulnerability Database (NVD)
LinuxLinux Kernel Version >= 3.1 < 3.2.44
LinuxLinux Kernel Version >= 3.3 < 3.4.49
LinuxLinux Kernel Version >= 3.5 < 3.8.8
RedhatEnterprise Linux Version6.0
RedhatEnterprise Mrg Version2.0
SuseLinux Enterprise Desktop Version11 Updatesp3
SuseLinux Enterprise Server Version11 Updatesp3 SwPlatform-
SuseLinux Enterprise Server Version11 Updatesp3 Editionvmware
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.34% 0.557
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C