Linux kernel libceph NULL function pointer dereference (CVE-2013-1059)
http://hkpco.kr/advisory/CVE-2013-1059.txt
This is very brief advisory just to record the vulnerability which I discovered in my spare time.A remote attacker, malicious ceph monitor, can make an exploit to cause a denial-of-service condition by sending the crafted auth_reply message.It could possibly lead to another impacts such as remote code execution if some other vulnerabilities are combined.An explanation is based on linux kernel 3.10 which is latest version now.
최근 덧글