Lucene search

K
cve[email protected]CVE-2007-3843
HistoryAug 09, 2007 - 9:17 p.m.

CVE-2007-3843

2007-08-0921:17:00
web.nvd.nist.gov
42
3
linux kernel
cve-2007-3843
cifs
network traffic
security signatures
remote attacks

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6

Confidence

Low

EPSS

0.02

Percentile

89.1%

The Linux kernel before 2.6.23-rc1 checks the wrong global variable for the CIFS sec mount option, which might allow remote attackers to spoof CIFS network traffic that the client configured for security signatures, as demonstrated by lack of signing despite sec=ntlmv2i in a SetupAndX request.

Affected configurations

NVD
Node
linuxlinux_kernelRange2.6.22rc6
VendorProductVersionCPE
linuxlinux_kernelcpe:/o:linux:linux_kernel::rc6::

Social References

More

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6

Confidence

Low

EPSS

0.02

Percentile

89.1%