CVE-2007-2875
published 2007-06-11CVE-2007-2875: Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4, when the cpuset filesystem is mounted…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.44%
35.9th percentile
Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4, when the cpuset filesystem is mounted, allows local users to obtain kernel memory contents by using a large offset when reading the /dev/cpuset/tasks file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| linux | linux_kernel | < 2.6.20.13 | 2.6.20.13 |
| linux | linux_kernel | >= 2.6.21 < 2.6.21.4 | 2.6.21.4 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_ubuntu7.8HIGH
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2007-08-31·CVSS 4.9
CVE-2007-2525 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
A flaw was discovered in the PPP over Ethernet implementation. Local
attackers could manipulate ioctls and cause kernel memory consumption
leading to a denial of service. (CVE-2007-2525)
An integer underflow was discovered in the cpuset filesystem. If mounted,
local attackers could obtain kernel memory using large file offsets while
reading the tasks file. This could disclose sensitive data. (CVE-2007-2875)
Vilmos Nebehaj discovered that the SCTP netfilter code did not correctly
validate certain states. A remote attacker could send a specially crafted
packet causing a denial of service. (CVE-2007-2876)
Luca Tettamanti discovered a flaw in the VFAT compat ioctls on 64-bit
systems. A local attacker could corrupt a
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2007-07-19·CVSS 7.8
CVE-2006-4623 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
A flaw was discovered in dvb ULE decapsulation. A remote attacker could
send a specially crafted message and cause a denial of service.
(CVE-2006-4623)
The compat_sys_mount function allowed local users to cause a denial of
service when mounting a smbfs filesystem in compatibility mode.
(CVE-2006-7203)
The Omnikey CardMan 4040 driver (cm4040_cs) did not limit the size of
buffers passed to read() and write(). A local attacker could exploit
this to execute arbitrary code with kernel privileges. (CVE-2007-0005)
Due to an variable handling flaw in the ipv6_getsockopt_sticky()
function a local attacker could exploit the getsockopt() calls to read
arbitrary kernel memory. This could disclose sensitive data.
(CVE-2007-1
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2007-07-18·CVSS 4.0
CVE-2007-2242 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
The compat_sys_mount function allowed local users to cause a denial of
service when mounting a smbfs filesystem in compatibility mode.
(CVE-2006-7203)
The Omnikey CardMan 4040 driver (cm4040_cs) did not limit the size of
buffers passed to read() and write(). A local attacker could exploit
this to execute arbitrary code with kernel privileges. (CVE-2007-0005)
Due to a variable handling flaw in the ipv6_getsockopt_sticky()
function a local attacker could exploit the getsockopt() calls to
read arbitrary kernel memory. This could disclose sensitive data.
(CVE-2007-1000)
Ilja van Sprundel discovered that Bluetooth setsockopt calls could leak
kernel memory contents via an uninitialized stack buffer. A local
attacker c
Red Hat
cpuset information leak
vendor_redhat·2007-06-07·CVSS 2.1
CVE-2007-2875 [LOW] cpuset information leak
cpuset information leak
Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4, when the cpuset filesystem is mounted, allows local users to obtain kernel memory contents by using a large offset when reading the /dev/cpuset/tasks file.
GHSA
GHSA-xcg5-vp9v-hx6x: Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2
ghsa_unreviewed·2022-05-01
CVE-2007-2875 [LOW] GHSA-xcg5-vp9v-hx6x: Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2
Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4, when the cpuset filesystem is mounted, allows local users to obtain kernel memory contents by using a large offset when reading the /dev/cpuset/tasks file.
No detection rules found.
No public exploits indexed.
arXiv
A Scalable Shannon Entropy Estimator
arxiv_fulltext·2022-06-02
A Scalable Shannon Entropy Estimator
A Scalable Shannon Entropy Estimator is available at https://github.com/meelgroup/entropyestimation. A preliminary version of this work appears at International Conference on Computer-Aided Verification, CAV, 2022. The names of authors are sorted alphabetically and the order does not reflect contribution.
Priyanka Golia
Indian Institute of Technology Kanpur
National University of Singapore
Brendan Juba
Washington University in St. Louis
Kuldeep S. Meel
National University of Singapore
## Abstract
We revisit the well-studied problem of estimating the Shannon entropy of a
probability distribution,
now given access to a probability-revealing conditional
sampling oracle. In this model, the oracle takes as input the representation
of a set S, and returns a sample from the distribution o
arXiv
Quantifying Information Leak Vulnerabilities
arxiv_fulltext·2010-07-06
Quantifying Information Leak Vulnerabilities
Quantifying Information Leak Vulnerabilities
Jonathan Heusser^
Pasquale Malacaria^
6 July 2010, [email protected] [email protected]
## Abstract
Leakage of confidential information represents a serious security risk.
Despite a number of novel, theoretical advances, it has been unclear if and how quantitative approaches to measuring leakage of confidential information could be applied to substantial, real-world programs. This is mostly due to the high complexity of computing precise leakage quantities.
In this paper, we introduce a technique which makes it possible to decide if a program conforms to a quantitative policy which scales to large state-spaces with the help of bounded model checking.
Our technique is applied to a number of officially reported information leak v
Bugzilla
CVE-2007-2875 cpuset information leak
bugzilla·2007-06-26·CVSS 2.1
CVE-2007-2875 [LOW] CVE-2007-2875 cpuset information leak
CVE-2007-2875 cpuset information leak
From iDefense:
Local exploitation of an information disclosure vulnerability within the
Linux Kernel allows attackers to obtain sensitive information from
kernel memory.
This vulnerability specifically exists in the "cpuset_tasks_read"
function. This function is responsible for supplying user-land
processes with data when they read from the /dev/cpuset/tasks file. The
code excerpt below shows the problem area.
1754 if (*ppos + nbytes > ctr->bufsz)
1755 nbytes = ctr->bufsz - *ppos;
1756 if (copy_to_user(buf, ctr->buf + *ppos, nbytes))
By reading from an offset (*ppos) larger than the contents of the file,
an attacker can cause an integer underflow to occur in the subtraction
on line 1755. This will result in the "copy_to_user" function on line
1756
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.13http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.21.4http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=541http://osvdb.org/37113http://secunia.com/advisories/26133http://secunia.com/advisories/26139http://secunia.com/advisories/26620http://secunia.com/advisories/26647http://secunia.com/advisories/26760http://secunia.com/advisories/27227http://www.debian.org/security/2007/dsa-1363http://www.mandriva.com/security/advisories?name=MDKSA-2007:171http://www.mandriva.com/security/advisories?name=MDKSA-2007:196http://www.novell.com/linux/security/advisories/2007_53_kernel.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0705.htmlhttp://www.securityfocus.com/bid/24389http://www.securitytracker.com/id?1018211http://www.ubuntu.com/usn/usn-486-1http://www.ubuntu.com/usn/usn-489-1http://www.ubuntu.com/usn/usn-510-1http://www.vupen.com/english/advisories/2007/2105https://exchange.xforce.ibmcloud.com/vulnerabilities/34779https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9251http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.13http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.21.4http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=541http://osvdb.org/37113http://secunia.com/advisories/26133http://secunia.com/advisories/26139http://secunia.com/advisories/26620http://secunia.com/advisories/26647http://secunia.com/advisories/26760http://secunia.com/advisories/27227http://www.debian.org/security/2007/dsa-1363http://www.mandriva.com/security/advisories?name=MDKSA-2007:171http://www.mandriva.com/security/advisories?name=MDKSA-2007:196http://www.novell.com/linux/security/advisories/2007_53_kernel.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0705.htmlhttp://www.securityfocus.com/bid/24389http://www.securitytracker.com/id?1018211http://www.ubuntu.com/usn/usn-486-1http://www.ubuntu.com/usn/usn-489-1http://www.ubuntu.com/usn/usn-510-1http://www.vupen.com/english/advisories/2007/2105https://exchange.xforce.ibmcloud.com/vulnerabilities/34779https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9251
2007-06-11
Published