Lucene search

K
cveRedhatCVE-2007-0001
HistoryMar 02, 2007 - 9:18 p.m.

CVE-2007-0001

2007-03-0221:18:00
redhat
web.nvd.nist.gov
37
nvd
cve-2007-0001
rhel
kernel
file watch
denial of service

CVSS2

4.7

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:N/A:C

AI Score

5.8

Confidence

High

EPSS

0

Percentile

9.7%

The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9 allows local users to cause a denial of service (kernel panic) by replacing a watched file, which does not cause the watch on the old inode to be dropped.

Affected configurations

Nvd
Node
redhatenterprise_linuxMatch4.0linux_kernel_2.6.9
VendorProductVersionCPE
redhatenterprise_linux4.0cpe:/o:redhat:enterprise_linux:4.0:::

CVSS2

4.7

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:N/A:C

AI Score

5.8

Confidence

High

EPSS

0

Percentile

9.7%