VDB
CVE-2013-2224
CVE-2013-2224
PUBLISHED
CVSS 6.900000095367432 MEDIUM
A certain Red Hat patch for the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 allows local users to cause a denial of service (invalid free operation and system crash) or possibly gain privileges via a sendmsg system call with the IP_RETOPTS option, as demonstrated by hemlock.c. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-3552.
EPSS 0.18% · 39.8th percentile
Risk Scores
CVSS 2.0
6.900000095367432
EPSS Score
0.18%
39.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| redhat | enterprise_linux | 6.0 |
Exploit Intelligence
Timeline
- Jul 4, 2013 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 16, 2023 EPSS Score
References
- RHSA-2013:1166 vendor-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=979936 url
- RHSA-2013:1173 vendor-advisory
- [oss-security] 20130630 Re: CVE request: Kernel 2.6.32+ IP_RETOPTS Buffer Poisoning DoS mailing-list
- RHSA-2013:1450 vendor-advisory
- http://www.vmware.com/security/advisories/VMSA-2013-0015.html advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-2224 advisory