PT-2007-1729 · Grsecurity · Grsecurity Pax

Published

2007-01-16

·

Updated

2025-01-17

·

CVE-2007-0257

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions grsecurity PaX (affected versions not specified)
Description The issue concerns an unspecified vulnerability in the expand stack function, potentially allowing local users to gain privileges through unspecified vectors. However, the grsecurity developer has disputed this issue, stating that the function in question is trivial and has been checked for vulnerabilities. The developer also references a past disclosure that was not proven. As of 20070120, the original researcher released demonstration code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2007-0257

Affected Products

Grsecurity Pax