Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including format string specifiers in an fwpostfix modprobe parameter, leading to improper construction of an error message.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2745-1 | linux security update |
Debian DSA |
DSA-2766-1 | linux-2.6 security update |
EUVD |
EUVD-2013-2791 | Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including format string specifiers in an fwpostfix modprobe parameter, leading to improper construction of an error message. |
Ubuntu USN |
USN-1899-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-1900-1 | Linux kernel (EC2) vulnerabilities |
Ubuntu USN |
USN-1914-1 | Linux kernel vulnerability |
Ubuntu USN |
USN-1915-1 | Linux kernel (Quantal HWE) vulnerability |
Ubuntu USN |
USN-1917-1 | Linux kernel vulnerability |
Ubuntu USN |
USN-1918-1 | Linux kernel (OMAP4) vulnerability |
Ubuntu USN |
USN-1919-1 | Linux kernel vulnerability |
Ubuntu USN |
USN-1920-1 | Linux kernel (OMAP4) vulnerability |
Ubuntu USN |
USN-1930-1 | Linux kernel (OMAP4) vulnerabilities |
Ubuntu USN |
USN-1936-1 | Linux kernel (Raring HWE) vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2024-08-06T15:52:20.476Z
Reserved: 2013-04-11T00:00:00
Link: CVE-2013-2852
No data.
Status : Deferred
Published: 2013-06-07T14:03:20.033
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-2852
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN