Lucene search

K
cveMitreCVE-2007-1734
HistoryMar 28, 2007 - 10:19 p.m.

CVE-2007-1734

2007-03-2822:19:00
mitre
web.nvd.nist.gov
32
cve-2007-1734
linux kernel
dccp
security vulnerability
memory leak
denial of service

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6

Confidence

Low

EPSS

0.001

Percentile

26.3%

The DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later does not verify the upper bounds of the optlen value, which allows local users running on certain architectures to read kernel memory or cause a denial of service (oops), a related issue to CVE-2007-1730.

Affected configurations

Nvd
Node
linuxlinux_kernelMatch2.6.20
OR
linuxlinux_kernelMatch2.6.20.1
OR
linuxlinux_kernelMatch2.6.20.2
VendorProductVersionCPE
linuxlinux_kernel2.6.20.1cpe:/o:linux:linux_kernel:2.6.20.1:::
linuxlinux_kernel2.6.20.2cpe:/o:linux:linux_kernel:2.6.20.2:::
linuxlinux_kernel2.6.20cpe:/o:linux:linux_kernel:2.6.20:::

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6

Confidence

Low

EPSS

0.001

Percentile

26.3%