LOW · 1.2

CVE-2012-2313

The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet ...

Vulnerability Description

The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.

CVSS Score

1.2

LOW

AV:L/AC:H/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
LinuxLinux Kernel<= 3.3.6
NovellSuse Linux Enterprise Server10.0
RedhatEnterprise Linux5
RedhatEnterprise Linux Desktop5.0
RedhatEnterprise Linux Eus5.6.z
RedhatEnterprise Linux Long Life5.6
RedhatEnterprise Linux Server Aus6.2
RedhatEnterprise Linux Server Eus6.1.z

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-2313?

CVE-2012-2313 is a vulnerability with a CVSS score of 1.2 (LOW). The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet ...

How severe is CVE-2012-2313?

CVE-2012-2313 has been rated LOW with a CVSS base score of 1.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-2313?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Novell Suse Linux Enterprise Server, Redhat Enterprise Linux, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Eus.