2.1
CVSSv2

CVE-2013-0160

Published: 18/02/2013 Updated: 29/11/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Linux kernel up to and including 3.7.9 allows local users to obtain sensitive information about keystroke timing by using the inotify API on the /dev/ptmx device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 3.0

linux linux kernel 3.0.38

linux linux kernel 3.0.35

linux linux kernel 3.0.23

linux linux kernel 3.0.20

linux linux kernel 3.0.15

linux linux kernel 3.0.12

linux linux kernel 3.0.4

linux linux kernel 3.0.3

linux linux kernel 3.0.7

linux linux kernel 3.0.31

linux linux kernel 3.1

linux linux kernel 3.1.6

linux linux kernel 3.1.5

linux linux kernel 3.2.11

linux linux kernel 3.0.44

linux linux kernel 3.0.37

linux linux kernel 3.0.24

linux linux kernel 3.0.22

linux linux kernel 3.0.17

linux linux kernel 3.0.14

linux linux kernel 3.0.26

linux linux kernel 3.0.25

linux linux kernel 3.0.33

linux linux kernel 3.0.30

linux linux kernel 3.0.8

linux linux kernel 3.1.8

linux linux kernel 3.1.7

linux linux kernel 3.2.1

linux linux kernel 3.2.10

linux linux kernel 3.2.4

linux linux kernel 3.2.3

linux linux kernel 3.2.21

linux linux kernel 3.2

linux linux kernel 3.2.8

linux linux kernel 3.2.9

linux linux kernel 3.2.18

linux linux kernel 3.2.19

linux linux kernel 3.3

linux linux kernel 3.3.5

linux linux kernel 3.3.8

linux linux kernel 3.4.7

linux linux kernel 3.4.8

linux linux kernel 3.4

linux linux kernel 3.0.36

linux linux kernel 3.0.41

linux linux kernel 3.0.21

linux linux kernel 3.0.18

linux linux kernel 3.0.13

linux linux kernel 3.0.10

linux linux kernel 3.0.2

linux linux kernel 3.0.1

linux linux kernel 3.0.6

linux linux kernel 3.0.28

linux linux kernel 3.1.4

linux linux kernel 3.1.3

linux linux kernel 3.1.2

linux linux kernel 3.2.26

linux linux kernel 3.2.27

linux linux kernel 3.2.23

linux linux kernel 3.2.30

linux linux kernel 3.2.14

linux linux kernel 3.2.15

linux linux kernel 3.3.2

linux linux kernel 3.3.4

linux linux kernel 3.4.10

linux linux kernel 3.4.11

linux linux kernel 3.4.4

linux linux kernel 3.4.2

linux linux kernel 3.4.1

linux linux kernel 3.4.18

linux linux kernel 3.4.19

linux linux kernel 3.5.2

linux linux kernel 3.5.3

linux linux kernel 3.7.2

linux linux kernel 3.7.3

linux linux kernel 3.0.43

linux linux kernel 3.0.42

linux linux kernel 3.0.39

linux linux kernel 3.0.40

linux linux kernel 3.0.19

linux linux kernel 3.0.16

linux linux kernel 3.0.11

linux linux kernel 3.0.27

linux linux kernel 3.0.34

linux linux kernel 3.0.32

linux linux kernel 3.0.5

linux linux kernel 3.0.9

linux linux kernel 3.0.29

linux linux kernel 3.1.10

linux linux kernel 3.1.9

linux linux kernel 3.1.1

linux linux kernel 3.2.28

linux linux kernel 3.2.5

linux linux kernel 3.2.29

linux linux kernel 3.2.22

linux linux kernel 3.2.6

linux linux kernel 3.2.7

linux linux kernel 3.2.16

linux linux kernel 3.2.17

linux linux kernel 3.3.6

linux linux kernel 3.3.7

linux linux kernel 3.4.12

linux linux kernel 3.4.6

linux linux kernel 3.4.16

linux linux kernel 3.4.17

linux linux kernel 3.4.24

linux linux kernel 3.4.23

linux linux kernel 3.5.6

linux linux kernel 3.5.7

linux linux kernel 3.6.9

linux linux kernel 3.7.4

linux linux kernel 3.7.5

linux linux kernel 3.2.25

linux linux kernel 3.2.2

linux linux kernel 3.2.24

linux linux kernel 3.2.12

linux linux kernel 3.2.13

linux linux kernel 3.2.20

linux linux kernel 3.3.3

linux linux kernel 3.3.1

linux linux kernel 3.4.13

linux linux kernel 3.4.9

linux linux kernel 3.4.5

linux linux kernel 3.4.3

linux linux kernel 3.4.20

linux linux kernel 3.4.21

linux linux kernel 3.5.5

linux linux kernel 3.5.1

linux linux kernel 3.7

linux linux kernel 3.7.1

linux linux kernel 3.7.8

linux linux kernel 3.7.9

linux linux kernel 3.4.14

linux linux kernel 3.4.15

linux linux kernel 3.4.22

linux linux kernel 3.5.4

linux linux kernel 3.6.10

linux linux kernel 3.6.11

linux linux kernel 3.7.6

linux linux kernel 3.7.7

Vendor Advisories

Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service, information leak or privilege escalation The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2013-0160 vladz reported a timing leak with the /dev/ptmx character device A local user could use this to d ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
The system could be made to crash or run programs as an administrator ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...

Exploits

#!/bin/bash # ptmx-su-pwdlensh -- This PoC determine the password length of a local # user who runs "su -" Done thanks to the ptmx keystroke timing attack # (CVE-2013-0160) See vladzdevzerofr/013_ptmx-timingphp for # more information # # Tested on Debian 605 (kernel 2632-5-amd64) # # "THE BEER-WARE LICENSE" (Revision 42): # &l ...
This proof of concept exploit determines the password length of a local user who runs "su -" ...