CVE Vulnerabilities

CVE-2007-1000

Published: Mar 12, 2007 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The ipv6_getsockopt_sticky function in net/ipv6/ipv6_sockglue.c in the Linux kernel before 2.6.20.2 allows local users to read arbitrary kernel memory via certain getsockopt calls that trigger a NULL dereference.

Affected Software

Name Vendor Start Version End Version
Linux_kernel Linux * 2.6.20.1 (including)
Linux-source-2.6.15 Ubuntu dapper *
Linux-source-2.6.17 Ubuntu edgy *
Linux-source-2.6.20 Ubuntu feisty *
Red Hat Enterprise Linux 5 RedHat kernel-0:2.6.18-8.1.3.el5 *

References