Vulnerability Description
WEB-DAV Linux File System (davfs2) 1.4.6 and 1.4.7 allow local users to gain privileges via unknown attack vectors in (1) kernel_interface.c and (2) mount_davfs.c, related to the "system" function.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Werner Baumann | Davfs2 | 1.4.6 |
Related Weaknesses (CWE)
References
- http://osvdb.org/97416
- http://osvdb.org/97417
- http://savannah.nongnu.org/bugs/?40034Patch
- http://seclists.org/oss-sec/2013/q3/627Patch
- http://www.debian.org/security/2013/dsa-2765
- http://www.securityfocus.com/bid/62445
- https://security.gentoo.org/glsa/201612-02
- http://osvdb.org/97416
- http://osvdb.org/97417
- http://savannah.nongnu.org/bugs/?40034Patch
- http://seclists.org/oss-sec/2013/q3/627Patch
- http://www.debian.org/security/2013/dsa-2765
- http://www.securityfocus.com/bid/62445
- https://security.gentoo.org/glsa/201612-02
FAQ
What is CVE-2013-4362?
CVE-2013-4362 is a vulnerability with a CVSS score of 7.2 (HIGH). WEB-DAV Linux File System (davfs2) 1.4.6 and 1.4.7 allow local users to gain privileges via unknown attack vectors in (1) kernel_interface.c and (2) mount_davfs.c, related to the "system" function.
How severe is CVE-2013-4362?
CVE-2013-4362 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-4362?
Check the references section above for vendor advisories and patch information. Affected products include: Werner Baumann Davfs2.