CVE-2013-2852

Description

Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including format string specifiers in an fwpostfix modprobe parameter, leading to improper construction of an error message.

Risk Information

Base Score
8.4
MODERATE
Vector
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.237

Associated Vulnerability

VulnerabilityOS Platform
Linux kernel (USN-1914-1) linux-image-3.2.0-51-generic_3.2.0-51.77_i386.debLinux
Linux kernel (USN-1914-1) linux-image-3.2.0-51-generic_3.2.0-51.77_amd64.debLinux
Linux kernel (USN-1914-1) linux-image-3.2.0-51-virtual_3.2.0-51.77_i386.debLinux
Linux kernel (USN-1914-1) linux-image-3.2.0-51-virtual_3.2.0-51.77_amd64.debLinux
Linux kernel (USN-1914-1) linux-image-3.2.0-51-generic-pae_3.2.0-51.77_i386.debLinux
Linux hardware enablement kernel from Quantal (USN-1915-1) linux-image-3.5.0-37-generic_3.5.0-37.58~precise1_i386.debLinux
Linux hardware enablement kernel from Quantal (USN-1915-1) linux-image-3.5.0-37-generic_3.5.0-37.58~precise1_amd64.debLinux
Linux hardware enablement kernel from Raring (USN-1916-1) linux-image-3.8.0-27-generic_3.8.0-27.40~precise3_i386.debLinux
Linux hardware enablement kernel from Raring (USN-1916-1) linux-image-3.8.0-27-generic_3.8.0-27.40~precise3_amd64.debLinux
Linux hardware enablement kernel from Raring (USN-1936-1) linux-image-3.8.0-29-generic_3.8.0-29.42~precise1_i386.debLinux
Linux hardware enablement kernel from Raring (USN-1936-1) linux-image-3.8.0-29-generic_3.8.0-29.42~precise1_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234