First published: Wed Mar 28 2007(Updated: )
Integer signedness error in the DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later allows local users to read kernel memory or cause a denial of service (oops) via a negative optlen value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | =2.6.20 | |
Linux Kernel | =2.6.20.2 | |
Linux Kernel | =2.6.20.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1730 is considered a medium severity vulnerability that can lead to information disclosure or a denial of service.
To fix CVE-2007-1730, it is advised to upgrade the Linux kernel to a version later than 2.6.20.2.
CVE-2007-1730 affects local users on systems running Linux kernel versions 2.6.20 and later.
CVE-2007-1730 enables local users to potentially read kernel memory or crash the kernel.
CVE-2007-1730 is applicable to any Linux distribution using the vulnerable kernel versions, including custom setups.