6.9

CVE-2007-0005

Multiple buffer overflows in the (1) read and (2) write handlers in the Omnikey CardMan 4040 driver in the Linux kernel before 2.6.21-rc3 allow local users to gain privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Omnikey.AaitgOmnikey Cardman 4040
   LinuxLinux Kernel Updaterc2 Version <= 2.6.21
   LinuxLinux Kernel Version2.6.21
   LinuxLinux Kernel Version2.6.21 Updaterc1
   LinuxLinux Kernel Version2.6.21.1
   LinuxLinux Kernel Version2.6.21.2
   LinuxLinux Kernel Version2.6.21.3
   LinuxLinux Kernel Version2.6.21.4
   LinuxLinux Kernel Version2.6.21.5
   LinuxLinux Kernel Version2.6.21.6
   LinuxLinux Kernel Version2.6.21.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.62% 0.447
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://secunia.com/advisories/25691
Vendor Advisory
http://www.securityfocus.com/archive/1/471457
http://secunia.com/advisories/26139
Vendor Advisory
http://www.ubuntu.com/usn/usn-489-1
http://secunia.com/advisories/24777
Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2007:078
http://www.redhat.com/support/errata/RHSA-2007-0099.html
Vendor Advisory
http://secunia.com/advisories/25078
Vendor Advisory
http://www.debian.org/security/2007/dsa-1286
http://fedoranews.org/cms/node/2787
http://fedoranews.org/cms/node/2788
http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.21-rc3
Patch
Vendor Advisory
http://secunia.com/advisories/24436
Vendor Advisory
http://secunia.com/advisories/24518
Vendor Advisory
http://secunia.com/advisories/24901
Vendor Advisory
http://secunia.com/advisories/26133
Vendor Advisory
http://www.osvdb.org/33023
http://www.securityfocus.com/archive/1/462300/100/0/threaded
http://www.securityfocus.com/bid/22870
http://www.ubuntu.com/usn/usn-486-1
http://www.vupen.com/english/advisories/2007/0872
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/32880
https://issues.rpath.com/browse/RPL-1035
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11238