[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249982

 
 

909

 
 

195748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-3848Date: (C)2007-08-14   (M)2024-02-22


Linux kernel 2.4.35 and other versions allows local users to send arbitrary signals to a child process that is running at higher privileges by causing a setuid-root parent process to die, which delivers an attacker-controlled parent process death signal (PR_SET_PDEATHSIG).

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 1.9
Exploit Score: 3.4
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
http://www.securityfocus.com/archive/1/476464/100/0/threaded
http://marc.info/?l=bugtraq&m=118711306802632&w=2
http://www.securityfocus.com/archive/1/476538/100/0/threaded
http://www.securityfocus.com/archive/1/476677/100/0/threaded
http://www.securityfocus.com/archive/1/476803/100/0/threaded
BID-25387
SECUNIA-26450
SECUNIA-26500
SECUNIA-26643
SECUNIA-26651
SECUNIA-26664
SECUNIA-27212
SECUNIA-27227
SECUNIA-27322
SECUNIA-27436
SECUNIA-27747
SECUNIA-27913
SECUNIA-28806
SECUNIA-29058
SECUNIA-29570
SECUNIA-33280
DSA-1356
DSA-1503
DSA-1504
MDKSA-2007:195
MDKSA-2007:196
RHSA-2007:0939
RHSA-2007:0940
RHSA-2007:1049
RHSA-2008:0787
SUSE-SA:2007:053
SUSE-SA:2008:006
SUSE-SA:2008:017
USN-508-1
USN-509-1
USN-510-1
http://marc.info/?l=openwall-announce&m=118710356812637&w=2
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2007-3848
http://support.avaya.com/elmodocs2/security/ASA-2007-474.htm
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.4
https://issues.rpath.com/browse/RPL-1648
oval:org.mitre.oval:def:10120

CPE    1
cpe:/o:linux:linux_kernel
OVAL    3
oval:org.mitre.oval:def:8130
oval:org.mitre.oval:def:8063
oval:org.secpod.oval:def:500526

© SecPod Technologies