Vulnerability Description
Multiple integer overflows in Alchemy LCD frame-buffer drivers in the Linux kernel before 3.12 allow local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted mmap operations, related to the (1) au1100fb_fb_mmap function in drivers/video/au1100fb.c and the (2) au1200fb_fb_mmap function in drivers/video/au1200fb.c.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 2.6.12, < 3.2.53 |
Related Weaknesses (CWE)
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=Broken Link
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00003.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-02/msg00045.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/11/04/22Mailing ListThird Party Advisory
- http://www.ubuntu.com/usn/USN-2036-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2037-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2066-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2067-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2068-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2069-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2070-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2071-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2072-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2073-1Third Party Advisory
FAQ
What is CVE-2013-4511?
CVE-2013-4511 is a vulnerability with a CVSS score of 6.9 (MEDIUM). Multiple integer overflows in Alchemy LCD frame-buffer drivers in the Linux kernel before 3.12 allow local users to create a read-write memory mapping for the entirety of kernel memory, and consequent...
How severe is CVE-2013-4511?
CVE-2013-4511 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-4511?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.