CVE-2007-1189: Integer Overflow
Integer overflow in the envwrite function in the Alcatel-Lucent Bell Labs Plan 9 kernel allows local users to overwrite certain memory addresses with kernel memory via a large n argument, as demonstrated by (1) modifying the iseve function to gain privileges and (2) making the devpermcheck function grant unrestricted device permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1189?
CVE-2007-1189 has a high severity rating of 7.2.
How does CVE-2007-1189 impact the Bell Labs Plan 9 kernel?
CVE-2007-1189 allows local users to exploit an integer overflow to overwrite memory addresses in the kernel.
Who is affected by CVE-2007-1189?
Local users of the Bell Labs Plan 9 operating system are affected by CVE-2007-1189.
How can I mitigate CVE-2007-1189?
Mitigation of CVE-2007-1189 involves applying patches provided by the vendor for the Bell Labs Plan 9 kernel.
What type of vulnerability is CVE-2007-1189?
CVE-2007-1189 is classified as an integer overflow vulnerability.