Vulnerability Description
The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 3.3.6 |
| Novell | Suse Linux Enterprise Server | 10.0 |
| Redhat | Enterprise Linux | 5 |
| Redhat | Enterprise Linux Desktop | 5.0 |
| Redhat | Enterprise Linux Eus | 5.6.z |
| Redhat | Enterprise Linux Long Life | 5.6 |
| Redhat | Enterprise Linux Server Aus | 6.2 |
| Redhat | Enterprise Linux Server Eus | 6.1.z |
Related Weaknesses (CWE)
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=139447903326211&w=2Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1174.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1481.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1541.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1589.htmlThird Party Advisory
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.3.7Release Notes
- http://www.openwall.com/lists/oss-security/2012/05/04/8Mailing List
- http://www.securityfocus.com/bid/53965Third Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=818820Issue Tracking
- https://github.com/torvalds/linux/commit/1bb57e940e1958e40d51f2078f50c3a96a9b2d7ExploitPatch
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=139447903326211&w=2Third Party Advisory
FAQ
What is CVE-2012-2313?
CVE-2012-2313 is a vulnerability with a CVSS score of 1.2 (LOW). The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet ...
How severe is CVE-2012-2313?
CVE-2012-2313 has been rated LOW with a CVSS base score of 1.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-2313?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Novell Suse Linux Enterprise Server, Redhat Enterprise Linux, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Eus.