Heap-based Buffer Overflow in tg3_read_vpd Function in Linux Kernel

Heap-based Buffer Overflow in tg3_read_vpd Function in Linux Kernel

CVE-2013-1929 · MEDIUM Severity

AV:L/AC:M/AU:N/C:P/I:P/A:P

Heap-based buffer overflow in the tg3_read_vpd function in drivers/net/ethernet/broadcom/tg3.c in the Linux kernel before 3.8.6 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via crafted firmware that specifies a long string in the Vital Product Data (VPD) data structure.

Learn more about our Cis Benchmark Audit For Distribution Independent Linux.