LOW
core-dumping unreadable binaries via PT_INTERP
Published Feb 15, 2007
2.1
LOWCVSS 2.0
EPSS 0.41%
Description
Linux kernel 2.6.x before 2.6.20 allows local users to read unreadable binaries by using the interpreter (PT_INTERP) functionality and triggering a core dump, a variant of CVE-2004-1073.
Affected products
No data.
OR
- 2.6.0
- 2.6.1
- 2.6.2
- 2.6.3
- 2.6.4
- 2.6.5
- 2.6.6
- 2.6.7
- 2.6.8
- 2.6.8.1
- 2.6.9
- 2.6.10
- 2.6.11
- 2.6.11.1
- 2.6.11.2
- 2.6.11.3
- 2.6.11.4
- 2.6.11.5
- 2.6.11.6
- 2.6.11.7
- 2.6.11.8
- 2.6.11.9
- 2.6.11.10
- 2.6.11.11
- 2.6.11.12
- 2.6.12
- 2.6.12.1
- 2.6.12.2
- 2.6.12.3
- 2.6.12.4
- 2.6.12.5
- 2.6.12.6
- 2.6.13
- 2.6.13.1
- 2.6.13.2
- 2.6.13.3
- 2.6.13.4
- 2.6.13.5
- 2.6.14
- 2.6.14.1
- 2.6.14.2
- 2.6.14.3
- 2.6.14.4
- 2.6.14.5
- 2.6.14.6
- 2.6.14.7
- 2.6.15
- 2.6.15.1
- 2.6.15.2
- 2.6.15.3
- 2.6.15.4
- 2.6.15.5
- 2.6.15.6
- 2.6.15.7
- 2.6.16
- 2.6.16.1
- 2.6.16.2
- 2.6.16.3
- 2.6.16.4
- 2.6.16.5
- 2.6.16.6
- 2.6.16.7
- 2.6.16.8
- 2.6.16.9
- 2.6.16.10
- 2.6.16.11
- 2.6.16.12
- 2.6.16.13
- 2.6.16.14
- 2.6.16.15
- 2.6.16.16
- 2.6.16.17
- 2.6.16.18
- 2.6.16.19
- 2.6.16.20
- 2.6.16.21
- 2.6.16.22
- 2.6.16.23
- 2.6.16.24
- 2.6.16.25
- 2.6.16.26
- 2.6.16.27
- 2.6.16.28
- 2.6.16.29
- 2.6.16.30
- 2.6.16.31
- 2.6.16.32
- 2.6.16.33
- 2.6.16.34
- 2.6.16.35
- 2.6.16.36
- 2.6.16.37
- 2.6.16.38
- 2.6.16.39
- 2.6.16.40
- 2.6.16.41
- 2.6.17
- 2.6.17.1
- 2.6.17.2
- 2.6.17.3
- 2.6.17.4
- 2.6.17.5
- 2.6.17.6
- 2.6.17.7
- 2.6.17.8
- 2.6.17.9
- 2.6.17.10
- 2.6.17.11
- 2.6.17.12
- 2.6.17.13
- 2.6.17.14
- 2.6.18
- 2.6.18.1
- 2.6.18.2
- 2.6.18.3
- 2.6.18.4
- 2.6.18.5
- 2.6.18.6
- 2.6.19
- 2.6.19.2
- 2.6.19.3
- 2.6.20
No data.
Red Hat Enterprise Linux 4
kernel-0:2.6.9-55.0.2.EL
Fixed · RHSA-2007:0488
Red Hat Enterprise Linux 5
kernel-0:2.6.18-8.1.1.el5
Fixed · RHSA-2007:0099
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | kernel-0:2.6.9-55.0.2.EL | Fixed | RHSA-2007:0488 |
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-8.1.1.el5 | Fixed | RHSA-2007:0099 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (24)
- http://osvdb.org/35930 vdb-entryx_refsource_OSVDB
- http://rhn.redhat.com/errata/RHSA-2007-0488.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/24482 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/24752 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/24777 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/25078 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/25714 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25838 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26289 third-party-advisoryx_refsource_SECUNIA
- http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm x_refsource_CONFIRM
- http://www.debian.org/security/2007/dsa-1286 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2007/dsa-1304 vendor-advisoryx_refsource_DEBIAN
- http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt x_refsource_MISCVendor Advisory
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20 x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:060 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:078 vendor-advisoryx_refsource_MANDRIVA
- http://www.redhat.com/support/errata/RHSA-2007-0099.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/22903 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/usn-451-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2007-0958 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=243256 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2007-0958
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10343 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2007-0958
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 15, 2007
Updated Aug 7, 2024
Reserved Feb 15, 2007
Link CVE-2007-0958
CISA Vulnrichment
Updated n/a