CVE-2013-1929

Heap-based buffer overflow in the tg3_read_vpd function in drivers/net/ethernet/broadcom/tg3.c in the Linux kernel before 3.8.6 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via crafted firmware that specifies a long string in the Vital Product Data (VPD) data structure.

Date published : 2013-06-07

http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=715230a44310a8cf66fbfb5a46f9a62a9b2de424

http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.6