4.7
CVSSv2

CVE-2007-2172

Published: 22/04/2007 Updated: 07/11/2023
CVSS v2 Base Score: 4.7 | Impact Score: 6.9 | Exploitability Score: 3.4
VMScore: 418
Vector: AV:L/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

A typo in Linux kernel 2.6 prior to 2.6.21-rc6 and 2.4 prior to 2.4.35 causes RTA_MAX to be used as an array size instead of RTN_MAX, which leads to an "out of bound access" by the (1) dn_fib_props (dn_fib.c, DECNet) and (2) fib_props (fib_semantics.c, IPv4) functions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 2.6.21

linux linux kernel

debian debian linux 3.1

debian debian linux 4.0

canonical ubuntu linux 6.06

canonical ubuntu linux 7.04

canonical ubuntu linux 6.10

Vendor Advisories

Philipp Richter discovered that the AppleTalk protocol handler did not sufficiently verify the length of packets By sending a crafted AppleTalk packet, a remote attacker could exploit this to crash the kernel (CVE-2007-1357) ...
Synopsis Important: kernel security update Type/Severity Security Advisory: Important Topic Updated kernel packages that fix a number of security issues are nowavailable for Red Hat Enterprise Linux 21 running on 64-bit architecturesThis update has been rated as having important security impact by the Red ...
Synopsis Important: kernel security update Type/Severity Security Advisory: Important Topic Updated kernel packages that fix a number of security issues are nowavailable for Red Hat Enterprise Linux 21 running on 32-bit architecturesThis update has been rated as having important security impact by the Red ...
Several local and remote vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or the execution of arbitrary code The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-2172 Thomas Graf reported a typo in the IPv4 protocol handler that could be used by a local a ...
Several local and remote vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or the execution of arbitrary code The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-1353 Ilja van Sprundel discovered that kernel memory could be leaked via the Bluetooth setsoc ...
Several local and remote vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or the execution of arbitrary code The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2004-2731 infamous41md reported multiple integer overflows in the Sbus PROM driver that would allo ...

References

CWE-20http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.21-rc6http://www.securityfocus.com/bid/23447http://www.redhat.com/support/errata/RHSA-2007-0347.htmlhttp://secunia.com/advisories/25288http://support.avaya.com/elmodocs2/security/ASA-2007-287.htmhttp://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.35http://www.debian.org/security/2007/dsa-1356http://www.debian.org/security/2007/dsa-1363http://www.mandriva.com/security/advisories?name=MDKSA-2007:171http://www.mandriva.com/security/advisories?name=MDKSA-2007:196http://www.mandriva.com/security/advisories?name=MDKSA-2007:216http://rhn.redhat.com/errata/RHSA-2007-0488.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1049.htmlhttp://www.ubuntu.com/usn/usn-464-1http://secunia.com/advisories/25392http://secunia.com/advisories/25838http://secunia.com/advisories/26289http://secunia.com/advisories/26450http://secunia.com/advisories/25068http://secunia.com/advisories/26647http://secunia.com/advisories/26620http://secunia.com/advisories/27913http://www.debian.org/security/2008/dsa-1503http://www.debian.org/security/2008/dsa-1504http://secunia.com/advisories/29058http://secunia.com/advisories/33280http://www.redhat.com/support/errata/RHSA-2008-0787.htmlhttp://www.vupen.com/english/advisories/2007/2690https://exchange.xforce.ibmcloud.com/vulnerabilities/33979https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10764http://www.mail-archive.com/git-commits-head%40vger.kernel.org/msg08270.htmlhttp://www.mail-archive.com/git-commits-head%40vger.kernel.org/msg08269.htmlhttps://usn.ubuntu.com/464-1/https://nvd.nist.gov