CVE-2013-1813: High severity red hat enterprise linux vulnerability
util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1813?
CVE-2013-1813 is considered a moderate vulnerability due to the improper permission settings that can lead to unauthorized access by local users.
How do I fix CVE-2013-1813?
To fix CVE-2013-1813, upgrade BusyBox to version 1.21.0 or later where the permission issue is addressed.
Which versions of BusyBox are affected by CVE-2013-1813?
CVE-2013-1813 affects BusyBox versions prior to 1.21.0, including all versions up to and including 1.20.2.
What attack vectors are associated with CVE-2013-1813?
CVE-2013-1813 can allow local users to exploit the excessive permissions on parent directories to gain unauthorized access or execute arbitrary commands.
Is CVE-2013-1813 specific to any operating systems?
CVE-2013-1813 is especially relevant to systems running affected versions of BusyBox, commonly seen in certain distributions like Red Hat Enterprise Linux 6.0 and certain routers.