« Volver al listado

CVE-2013-2239

Estado: ModificadaMedia (4.7)—

vzkernel before 042stab080.2 in the OpenVZ modification for the Linux kernel 2.6.32 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via (1) a crafted ploop driver ioctl call, related to the ploop_getdevice_ioc function in drivers/block/ploop/dev.c, or (2) a crafted quotactl system call, related to the compat_quotactl function in fs/quota/quota.c.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-2239",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.7,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:C/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-11-12T14:35:11.353",
  "references": [
    {
      "url": "http://openwall.com/lists/oss-security/2013/07/04/9",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://wiki.openvz.org/Download/kernel/rhel6-testing/042stab080.2",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.debian.org/security/2013/dsa-2766",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugs.gentoo.org/show_bug.cgi?id=475762",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://security-tracker.debian.org/tracker/CVE-2013-2239",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://openwall.com/lists/oss-security/2013/07/04/9",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://wiki.openvz.org/Download/kernel/rhel6-testing/042stab080.2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2013/dsa-2766",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugs.gentoo.org/show_bug.cgi?id=475762",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security-tracker.debian.org/tracker/CVE-2013-2239",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "vzkernel before 042stab080.2 in the OpenVZ modification for the Linux kernel 2.6.32 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via (1) a crafted ploop driver ioctl call, related to the ploop_getdevice_ioc function in drivers/block/ploop/dev.c, or (2) a crafted quotactl system call, related to the compat_quotactl function in fs/quota/quota.c."
    },
    {
      "lang": "es",
      "value": "vzkernel anterior a versión 042stab080.2 en la modificación de OpenVZ para el kernel de Linux versión 2.6.32, no inicializa determinadas variables de longitud, lo que permite a usuarios locales obtener información confidencial de la memoria de la pila del kernel por medio de (1) una llamada ioctl del controlador ploop diseñada, relacionado con la  función ploop_getdevice_ioc en el archivo drivers/block/ploop/dev.c, o (2) una llamada de sistema quotactl diseñada, relacionada con la función compat_quotactl en fs/quota/quota.c."
    }
  ],
  "lastModified": "2026-06-16T23:53:00.073",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:openvz:vzkernel:2.6.32:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C297A326-053E-4AC0-9A82-18C75CE81808"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}