CVE-2013-1773 describes a buffer overflow vulnerability in the VFAT filesystem implementation of the Linux kernel before version 3.3, affecting various Linux distributions including Red Hat Enterprise Linux. This flaw allows local users to escalate privileges or cause a denial of service by performing a VFAT write operation on a filesystem mounted with the utf8 option, due to improper handling during UTF-8 to UTF-16 conversion. With a CVSS score of 6.2, it is considered a medium severity vulnerability, requiring local access and high attack complexity, but potentially leading to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or Metasploit/Nuclei modules, a proof-of-concept for a local denial of service crash exists on ExploitDB, and the vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:rc7:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.0:rc1:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.0:rc2:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.0:rc3:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.0:rc4:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:H/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.