Lucene search

K
cve[email protected]CVE-2007-5904
HistoryNov 09, 2007 - 6:46 p.m.

CVE-2007-5904

2007-11-0918:46:00
CWE-119
web.nvd.nist.gov
32
2
cifs vfs
linux kernel
buffer overflow
denial of service
remote code execution
smb
nvd

6.8 Medium

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:A/AC:H/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.037 Low

EPSS

Percentile

91.8%

Multiple buffer overflows in CIFS VFS in Linux kernel 2.6.23 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long SMB responses that trigger the overflows in the SendReceive function.

Affected configurations

NVD
Node
linuxlinux_kernelRange≀2.6.23

References

Social References

More

6.8 Medium

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:A/AC:H/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.037 Low

EPSS

Percentile

91.8%