VDB
CVE-2007-1388
CVE-2007-1388
PUBLISHED
CVSS 4.400000095367432 MEDIUM
The do_ipv6_setsockopt function in net/ipv6/ipv6_sockglue.c in Linux kernel before 2.6.20, and possibly other versions, allows local users to cause a denial of service (oops) by calling setsockopt with the IPV6_RTHDR option name and possibly a zero option length or invalid option value, which triggers a NULL pointer dereference.
EPSS 0.55% · 43.7th percentile
Risk Scores
CVSS 2.0
4.400000095367432
EPSS Score
0.55%
43.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| linux | linux_kernel | 2.6.11.5, 0, 2.6.0 |
| n/a | n/a | * |
Timeline
- Mar 10, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- USN-464-1 vendor-advisory
- ADV-2007-1122 vdb
- 23142 vdb
- MDKSA-2007:078 vendor-advisory
- https://issues.rpath.com/browse/RPL-1154 url
- 24777 third-party-advisory
- 25099 third-party-advisory
- RHSA-2007:0169 vendor-advisory
- 25080 third-party-advisory
- 25392 third-party-advisory
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.4 url
- 24901 third-party-advisory
- SUSE-SA:2007:029 vendor-advisory
- http://bugzilla.kernel.org/show_bug.cgi?id=8155 url
- oval:org.mitre.oval:def:11509 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2007-1388 advisory