The hidp_setup_hid function in net/bluetooth/hidp/core.c in the Linux kernel before 3.7.6 does not properly copy a certain name field, which allows local users to obtain sensitive information from kernel memory by setting a long name and making an HIDPCONNADD ioctl call.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2013-02-28T19:00:00

Updated: 2024-08-06T14:25:09.634Z

Reserved: 2012-12-06T00:00:00

Link: CVE-2013-0349

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2013-02-28T19:55:01.323

Modified: 2023-02-13T04:41:12.260

Link: CVE-2013-0349

cve-icon Redhat

Severity : Low

Publid Date: 2013-01-09T00:00:00Z

Links: CVE-2013-0349 - Bugzilla