CVE-2007-1865: Low severity redhat Enterprise Linux vulnerability
DISPUTED The ipv6getsockoptsticky function in the kernel in Red Hat Enterprise Linux (RHEL) Beta 5.1.0 allows local users to obtain sensitive information (kernel memory contents) via a negative value of the len parameter. NOTE: this issue has been disputed in a bug comment, stating that "len is ignored when copying header info to the user's buffer."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1865?
CVE-2007-1865 is a disputed vulnerability that is considered to allow local users to access sensitive kernel memory contents.
How do I fix CVE-2007-1865?
To mitigate CVE-2007-1865, it is recommended to update to a non-beta version of Red Hat Enterprise Linux that addresses this vulnerability.
Who is affected by CVE-2007-1865?
CVE-2007-1865 affects users of Red Hat Enterprise Linux 5.1.0 Beta.
What is the impact of CVE-2007-1865?
The impact of CVE-2007-1865 is the potential exposure of sensitive information from kernel memory to local users.
Is CVE-2007-1865 currently being disputed?
Yes, CVE-2007-1865 is currently disputed, with claims suggesting that the vulnerability may not exist as reported.