Executive Summary

Informations
Name CVE-2013-1813 First vendor Publication 2013-11-23
Vendor Cve Last vendor Modification 2020-08-27

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score 7.2 Attack Range Local
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 3.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1813

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-264 Permissions, Privileges, and Access Controls

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:26241
 
Oval ID: oval:org.mitre.oval:def:26241
Title: RHSA-2013:1732: busybox security and bug fix update (Low)
Description: util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors.
Family: unix Class: patch
Reference(s): RHSA-2013:1732-03
CESA-2013:1732
CVE-2013-1813
Version: 3
Platform(s): Red Hat Enterprise Linux 6
CentOS Linux 6
Product(s): busybox
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:27506
 
Oval ID: oval:org.mitre.oval:def:27506
Title: ELSA-2013-1732 -- busybox security and bug fix update (low)
Description: [1:1.15.1-20] - Resolves: #855832 'Installation from NFS: That directory could not be mounted from the server' by switching NFS mount default from UDP to TCP. There was another place (in uclibc this time) which used UDP.
Family: unix Class: patch
Reference(s): ELSA-2013-1732
CVE-2013-1813
Version: 3
Platform(s): Oracle Linux 6
Product(s): busybox
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 113
Os 1
Os 1

Nessus® Vulnerability Scanner

Date Description
2014-11-12 Name : The remote CentOS host is missing one or more security updates.
File : centos_RHSA-2013-1732.nasl - Type : ACT_GATHER_INFO
2013-12-03 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201312-02.nasl - Type : ACT_GATHER_INFO
2013-11-27 Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2013-1732.nasl - Type : ACT_GATHER_INFO
2013-11-21 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2013-1732.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
BUGTRAQ https://seclists.org/bugtraq/2019/Jun/14
CONFIRM http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=701965
http://git.busybox.net/busybox/commit/?id=4609f477c7e043a4f6147dfe6e86b775da2...
https://support.t-mobile.com/docs/DOC-21994
FULLDISC http://seclists.org/fulldisclosure/2019/Jun/18
http://seclists.org/fulldisclosure/2020/Aug/20
http://seclists.org/fulldisclosure/2020/Mar/15
MISC http://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switc...
MLIST http://lists.busybox.net/pipermail/busybox/2013-January/078864.html
REDHAT http://rhn.redhat.com/errata/RHSA-2013-1732.html

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
Date Informations
2024-02-02 01:22:38
  • Multiple Updates
2024-02-01 12:06:41
  • Multiple Updates
2023-09-05 12:21:24
  • Multiple Updates
2023-09-05 01:06:35
  • Multiple Updates
2023-09-02 12:21:25
  • Multiple Updates
2023-09-02 01:06:41
  • Multiple Updates
2023-08-22 12:19:08
  • Multiple Updates
2022-10-11 01:06:23
  • Multiple Updates
2021-05-05 01:13:07
  • Multiple Updates
2021-05-04 12:26:51
  • Multiple Updates
2021-04-22 01:32:32
  • Multiple Updates
2020-09-02 17:22:52
  • Multiple Updates
2020-05-24 01:10:57
  • Multiple Updates
2020-05-23 00:36:42
  • Multiple Updates
2019-06-14 05:20:26
  • Multiple Updates
2019-06-13 21:19:22
  • Multiple Updates
2019-06-13 13:19:23
  • Multiple Updates
2019-04-22 21:19:07
  • Multiple Updates
2018-09-25 12:09:21
  • Multiple Updates
2018-09-01 12:04:57
  • Multiple Updates
2017-11-30 12:02:07
  • Multiple Updates
2016-12-16 12:01:34
  • Multiple Updates
2016-06-30 21:20:58
  • Multiple Updates
2016-06-28 19:24:56
  • Multiple Updates
2016-04-26 23:01:30
  • Multiple Updates
2015-09-18 09:20:03
  • Multiple Updates
2014-11-13 13:26:43
  • Multiple Updates
2014-11-08 13:30:42
  • Multiple Updates
2014-02-28 13:22:07
  • Multiple Updates
2014-02-17 11:18:26
  • Multiple Updates
2013-11-25 21:20:08
  • Multiple Updates
2013-11-23 17:20:01
  • First insertion