Multiple array index errors in drivers/hid/hid-core.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11 allow physically proximate attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted device that provides an invalid Report ID.
Metrics
No CVSS v4.0
No CVSS v3.1
No CVSS v3.0
Access Vector Local
Access Complexity High
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
AV:L/AC:H/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
Vendors | Products |
---|---|
Linux |
|
Redhat |
|
Configuration 1 [-]
|
Package | CPE | Advisory | Released Date |
---|---|---|---|
Red Hat Enterprise Linux 5 | |||
kernel-0:2.6.18-371.8.1.el5 | cpe:/o:redhat:enterprise_linux:5 | RHSA-2014:0433 | 2014-04-24T00:00:00Z |
Red Hat Enterprise Linux 6 | |||
kernel-0:2.6.32-431.el6 | cpe:/o:redhat:enterprise_linux:6 | RHSA-2013:1645 | 2013-11-20T00:00:00Z |
Red Hat Enterprise MRG 2 | |||
kernel-rt-0:3.8.13-rt14.25.el6rt | cpe:/a:redhat:enterprise_mrg:2:server:el6 | RHSA-2013:1490 | 2013-10-31T00:00:00Z |
RHEV 3.X Hypervisor and Agents for RHEL-6 | |||
rhev-hypervisor6-0:6.5-20131115.0.3.2.el6_5 | cpe:/o:redhat:enterprise_linux:6::hypervisor | RHSA-2013:1527 | 2013-11-21T00:00:00Z |
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Chrome
Published: 2013-09-13T18:00:00
Updated: 2024-08-06T15:52:20.678Z
Reserved: 2013-04-11T00:00:00
Link: CVE-2013-2888
Vulnrichment
No data.
NVD
Status : Modified
Published: 2013-09-16T13:01:24.783
Modified: 2024-11-21T01:52:35.730
Link: CVE-2013-2888
Redhat