VulnerabilityModified
CVE-2007-0005
Multiple buffer overflows in the (1) read and (2) write handlers in the Omnikey CardMan 4040 driver in the Linux kernel before 2.6.21-rc3 allow local users to gain privileges.
MEDIUM 6.9EPSS 0.61%
Does this matter?
Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple buffer overflows in the (1) read and (2) write handlers in the Omnikey CardMan 4040 driver in the Linux kernel before 2.6.21-rc3 allow local users to gain privileges.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.61% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- omnikey.aaitg/omnikey cardman 4040
- Source
- secalert@redhat.com
References
- http://fedoranews.org/cms/node/2787
- http://fedoranews.org/cms/node/2788
- http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.21-rc3Patch, Vendor Advisory
- http://secunia.com/advisories/24436Vendor Advisory
- http://secunia.com/advisories/24518Vendor Advisory
- http://secunia.com/advisories/24777Vendor Advisory
- http://secunia.com/advisories/24901Vendor Advisory
- http://secunia.com/advisories/25078Vendor Advisory
- http://secunia.com/advisories/25691Vendor Advisory
- http://secunia.com/advisories/26133Vendor Advisory
- http://secunia.com/advisories/26139Vendor Advisory
- http://www.debian.org/security/2007/dsa-1286
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:078
- http://www.osvdb.org/33023
- http://www.redhat.com/support/errata/RHSA-2007-0099.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/462300/100/0/threaded
- http://www.securityfocus.com/archive/1/471457
- http://www.securityfocus.com/bid/22870
- http://www.ubuntu.com/usn/usn-486-1
- http://www.ubuntu.com/usn/usn-489-1
- http://www.vupen.com/english/advisories/2007/0872Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32880
- https://issues.rpath.com/browse/RPL-1035
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11238
- http://fedoranews.org/cms/node/2787
- http://fedoranews.org/cms/node/2788
- http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.21-rc3Patch, Vendor Advisory
- http://secunia.com/advisories/24436Vendor Advisory
- http://secunia.com/advisories/24518Vendor Advisory
- http://secunia.com/advisories/24777Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.