Released on: 2013-07-03
Updated on: 2013-07-06
Affected Systems:
Linux kernel <= 3.9
Description:
--------------------------------------------------------------------------------
Bugtraq id: 60953
CVE (CAN) ID: CVE-2013-2237
Linux Kernel is the Kernel of the Linux operating system.
In versions earlier than Linux kernel 3.9, the key_policy_policy_flush function in net/key/af_key.c does not initialize a structure member, so that local users can read the broadcast messages of the policy_policy interface of IPsec, attackers can exploit this vulnerability to obtain sensitive information.
<* Source: Michal Hocko
Link: https://github.com/torvalds/linux/commit/85dfb745ee40232876663ae206cba35f24ab2a40
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.nist.gov/cgi-bin/exit_nist.cgi? Bytes