[Forgot Password]
Login  Register Subscribe

23631

 
 

127000

 
 

102010

 
 

909

 
 

81059

 
 

123

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML view JSON

CVE-2007-4997Date: (C)2007-11-06   (M)2018-02-19


Integer underflow in the ieee80211_rx function in net/ieee80211/ieee80211_rx.c in the Linux kernel 2.6.x before 2.6.23 allows remote attackers to cause a denial of service (crash) via a crafted SKB length value in a runt IEEE 802.11 frame when the IEEE80211_STYPE_QOS_DATA flag is set, aka an "off-by-two error."

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score  : CVSS Score  : 7.1
Exploit Score: Exploit Score: 8.6
Impact Score : Impact Score : 6.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: Access Vector: NETWORK
Attack Complexity: Access Complexity: MEDIUM
Privileges Required: Authentication: NONE
User Interaction: Confidentiality: NONE
Scope: Integrity: NONE
Confidentiality: Availability: COMPLETE
Integrity:  
Availability:  
  





Reference:
BID-26337
SECUNIA-27555
SECUNIA-27614
SECUNIA-27824
SECUNIA-27912
SECUNIA-28033
SECUNIA-28162
SECUNIA-28170
SECUNIA-28706
SECUNIA-28806
SECUNIA-28971
ADV-2007-3718
DSA-1428
MDKSA-2007:226
MDKSA-2007:232
MDVSA-2008:008
MDVSA-2008:105
RHSA-2007:0993
RHSA-2007:1104
SUSE-SA:2007:059
SUSE-SA:2007:064
SUSE-SA:2008:006
USN-558-1
USN-574-1
USN-578-1
ftp://ftp.kernel.org/pub/linux/kernel/people/bunk/linux-2.6.16.y/testing/ChangeLog-2.6.16.57-rc1
http://git.kernel.org/?p=linux/kernel/git/avi/kvm.git;a=commitdiff;h=04045f98e0457aba7d4e6736f37eed189c48a5f7
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23
kernel-ieee80211-dos(38247)

CPE    1
cpe:/o:linux:linux_kernel:2.6.22.7
CWE    1
CWE-189
OVAL    1
oval:org.secpod.oval:def:301365

© 2013 SecPod Technologies