CVE-2013-1773

Priority
Medium
Description
Buffer overflow in the VFAT filesystem implementation in the Linux kernel
before 3.3 allows local users to gain privileges or cause a denial of
service (system crash) via a VFAT write operation on a filesystem with the
utf8 mount option, which is not properly handled during UTF-8 to UTF-16
conversion.
Ubuntu-Description
A flaw was discovered on the Linux kernel's VFAT filesystem driver when a
disk is mounted with the utf8 option (this is the default on Ubuntu). On a
system where disks/images can be auto-mounted or a FAT filesystem is
mounted an unprivileged user can exploit the flaw to gain root privileges.
References
Bugs
Package
Upstream:released (3.3~rc1)
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 11.10 (Oneiric Ocelot):DNE
Ubuntu 12.04 LTS (Precise Pangolin):not-affected (3.2.0-1602.5)
Ubuntu 12.10 (Quantal Quetzal):not-affected (3.5.0-1600.1)
Ubuntu 13.04 (Raring Ringtail):not-affected
Package
Upstream:released (3.3~rc1)
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):released (2.6.32-351.62)
Ubuntu 11.10 (Oneiric Ocelot):DNE
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Package
Upstream:released (3.3~rc1)
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):released (3.0.0-32.50~lucid1)
Ubuntu 11.10 (Oneiric Ocelot):DNE
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Package
Upstream:released (3.3~rc1)
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 11.10 (Oneiric Ocelot):ignored (abandoned)
Ubuntu 12.04 LTS (Precise Pangolin):ignored (abandoned)
Ubuntu 12.10 (Quantal Quetzal):ignored (abandoned)
Ubuntu 13.04 (Raring Ringtail):ignored (abandoned)
Package
Upstream:released (3.3~rc1)
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 11.10 (Oneiric Ocelot):ignored (abandoned)
Ubuntu 12.04 LTS (Precise Pangolin):ignored (abandoned)
Ubuntu 12.10 (Quantal Quetzal):ignored (abandoned)
Ubuntu 13.04 (Raring Ringtail):ignored (abandoned)
Package
Upstream:released (3.3~rc1)
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):ignored (abandoned)
Ubuntu 11.10 (Oneiric Ocelot):ignored (abandoned)
Ubuntu 12.04 LTS (Precise Pangolin):ignored (abandoned)
Ubuntu 12.10 (Quantal Quetzal):ignored (abandoned)
Ubuntu 13.04 (Raring Ringtail):ignored (abandoned)
Package
Upstream:released (3.3~rc1)
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 11.10 (Oneiric Ocelot):DNE
Ubuntu 12.04 LTS (Precise Pangolin):released (3.5.0-1.1~precise1)
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Patches:
Package
Upstream:released (3.3~rc1)
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life)
Ubuntu 11.10 (Oneiric Ocelot):DNE
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Package
Upstream:released (3.3~rc1)
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life)
Ubuntu 11.10 (Oneiric Ocelot):DNE
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Package
Source: linux (LP Ubuntu Debian)
Upstream:released (3.3~rc1)
Ubuntu 8.04 LTS (Hardy Heron):not-affected
Ubuntu 10.04 LTS (Lucid Lynx):released (2.6.32-46.105)
Ubuntu 11.10 (Oneiric Ocelot):released (3.0.0-32.50)
Ubuntu 12.04 LTS (Precise Pangolin):released (3.2.0-22.35)
Ubuntu 12.10 (Quantal Quetzal):not-affected (3.4.0-1.1)
Ubuntu 13.04 (Raring Ringtail):not-affected (3.7.0-0.1)
Patches:
Introduced by 74675a58507e769beee7d949dbed788af3c4139dFixed by 0720a06a7518c9d0c0125bd5d1f3b6264c55c3dd
Package
Upstream:released (3.3~rc1)
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 11.10 (Oneiric Ocelot):released (3.0.0-1222.36)
Ubuntu 12.04 LTS (Precise Pangolin):released (3.2.0-1412.15)
Ubuntu 12.10 (Quantal Quetzal):not-affected (3.4.0-1.1)
Ubuntu 13.04 (Raring Ringtail):not-affected
Package
Upstream:released (3.3~rc1)
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 11.10 (Oneiric Ocelot):ignored (abandoned)
Ubuntu 12.04 LTS (Precise Pangolin):ignored (abandoned)
Ubuntu 12.10 (Quantal Quetzal):ignored (abandoned)
Ubuntu 13.04 (Raring Ringtail):ignored (abandoned)
Package
Upstream:released (3.3~rc1)
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life, does not affect buildd)
Ubuntu 11.10 (Oneiric Ocelot):DNE
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
More Information

Valid XHTML 1.0 Strict

Updated: 2013-03-23 05:14:09 UTC (commit 6631)