Vulnerability Description
A denial of service vulnerability exists in some motherboard implementations of Intel e1000e/82574L network controller devices through 2013-02-06 where the device can be brought into a non-processing state when parsing 32 hex, 33 hex, or 34 hex byte values at the 0x47f offset. NOTE: A followup statement from Intel suggests that the root cause of this issue was an incorrectly configured EEPROM image.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | 82574L Controller Firmware | <= 2013-02-06 |
| Intel | 82574L Controller | - |
Related Weaknesses (CWE)
References
- http://blog.krisk.org/2013/02/packets-of-death.htmlTechnical DescriptionThird Party Advisory
- http://web.archive.org/web/20131205055429/https://communities.intel.com/communitVendor Advisory
- http://www.openwall.com/lists/oss-security/2013/02/12/3Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/02/12/4Mailing ListThird Party Advisory
- http://www.securitytracker.com/id/1028089Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85069Third Party AdvisoryVDB Entry
- http://blog.krisk.org/2013/02/packets-of-death.htmlTechnical DescriptionThird Party Advisory
- http://web.archive.org/web/20131205055429/https://communities.intel.com/communitVendor Advisory
- http://www.openwall.com/lists/oss-security/2013/02/12/3Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/02/12/4Mailing ListThird Party Advisory
- http://www.securitytracker.com/id/1028089Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85069Third Party AdvisoryVDB Entry
FAQ
What is CVE-2013-1634?
CVE-2013-1634 is a vulnerability with a CVSS score of 7.5 (HIGH). A denial of service vulnerability exists in some motherboard implementations of Intel e1000e/82574L network controller devices through 2013-02-06 where the device can be brought into a non-processing ...
How severe is CVE-2013-1634?
CVE-2013-1634 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-1634?
Check the references section above for vendor advisories and patch information. Affected products include: Intel 82574L Controller Firmware, Intel 82574L Controller.