Release date:
Updated on:
Affected Systems:
Linux kernel <= 3.8.6
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-1929
Linux Kernel is the Kernel of the Linux operating system.
The tg3_read_vpd function in drivers/net/ethernet/broadcom/tg3.c earlier than Linux kernel 3.8.6 has the heap buffer overflow vulnerability, attackers can exploit this vulnerability to specify long strings in the VPD data structure through specially crafted firmware to cause DoS or arbitrary code execution.
<* Source: vendor
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 949932
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kernel.org/
Https://git.kernel.org/linus/715230a44310a8cf66fbfb5a46f9a62a9b2de424