PT-2004-3760 · Linux+2 · Linux Kernel+2

Published

1970-01-01

·

Updated

2017-10-11

·

CVE-2007-1353

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Debian GNU/Linux kernel-image-2.4.27-4 versions Debian GNU/Linux kernel-pcmcia-modules-2.4.27-4 versions Debian GNU/Linux kernel-headers-2.4.27-4 versions Debian GNU/Linux hostap-modules-2.4.27-4 versions Debian GNU/Linux i2c-2.4.27-4 versions Debian GNU/Linux lm-sensors-2.4.27-4 versions Debian GNU/Linux pcmcia-modules-2.4.27-4 versions
Description The issue involves multiple vulnerabilities in various packages of the Debian GNU/Linux operating system, including kernel-image, kernel-pcmcia-modules, kernel-headers, hostap-modules, i2c, lm-sensors, and pcmcia-modules. These vulnerabilities can lead to a disruption of protected information and can be exploited remotely. According to the information from Mitre, the setsockopt function in the L2CAP and HCI Bluetooth support in the Linux kernel before 2.4.34.3 allows context-dependent attackers to read kernel memory and obtain sensitive information via unspecified vectors involving the copy from user function accessing an uninitialized stack buffer.
Recommendations As a temporary workaround, consider disabling the setsockopt function until a patch is available. Restrict access to the vulnerable kernel modules to minimize the risk of exploitation. Avoid using the copy from user function in the affected kernel versions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03581
BDU:2015-03582
BDU:2015-03583
BDU:2015-03584
BDU:2015-03585
BDU:2015-03586
BDU:2015-03587
BDU:2015-03588
BDU:2015-03589
BDU:2015-03590
BDU:2015-03591
BDU:2015-03592
BDU:2015-03593
BDU:2015-03594
BDU:2015-03595
BDU:2015-03596
BDU:2015-03597
BDU:2015-03598
BDU:2015-03599
BDU:2015-03600
BDU:2015-03601
BDU:2015-03602
BDU:2015-03603
BDU:2015-03604
BDU:2015-03605
BDU:2015-03606
BDU:2015-03607
BDU:2015-03608
BDU:2015-03609
BDU:2015-03610
BDU:2015-03611
BDU:2015-03612
BDU:2015-03613
BDU:2015-03614
BDU:2015-03615
BDU:2015-03616
BDU:2015-03617
BDU:2015-03618
BDU:2015-03619
BDU:2015-03620
BDU:2015-03621
BDU:2015-03622
BDU:2015-03623
BDU:2015-03624
BDU:2015-03625
BDU:2015-03626
BDU:2015-03627
BDU:2015-03628
BDU:2015-03629
BDU:2015-03630
BDU:2015-03631
BDU:2015-03632
BDU:2015-03633
BDU:2015-03634
BDU:2015-03635
BDU:2015-03636
BDU:2015-03637
BDU:2015-03638
BDU:2015-03639
BDU:2015-03640
BDU:2015-03641
BDU:2015-03642
BDU:2015-03643
BDU:2015-03644
BDU:2015-03645
BDU:2015-03646
BDU:2015-03647
BDU:2015-03648
BDU:2015-03649
BDU:2015-03650
BDU:2015-03651
BDU:2015-03652
BDU:2015-03653
BDU:2015-03654
CVE-2007-1353
DSA-1356-1
DSA-1503-1
DSA-1503-2
DSA-1504-1
RHSA-2007:0376
RHSA-2007:0488
RHSA-2007:0671
RHSA-2007:0672
RHSA-2007:0673
RHSA-2007_0376
RHSA-2007_0488

Affected Products

Debian
Linux Kernel
Red Hat