SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-3843

The Linux kernel before 2.6.23-rc1 checks the wrong global variable for the CIFS sec mount option, which might allow remote attackers to spoof CIFS network traffic that the client configured for security signatures, as demonstrated by lack of signing…

MEDIUM 4.3EPSS 2.62%

Does this matter?

Lower severity and a low EPSS score (2.62%). Track it; it rarely justifies an emergency change on its own.

Description

The Linux kernel before 2.6.23-rc1 checks the wrong global variable for the CIFS sec mount option, which might allow remote attackers to spoof CIFS network traffic that the client configured for security signatures, as demonstrated by lack of signing despite sec=ntlmv2i in a SetupAndX request.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
2.62% probability · 85th percentile
CISA KEV
Not listed
Affected
linux/linux kernel
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.