CVE-2007-6206
published 2007-12-04CVE-2007-6206: The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.43%
34.8th percentile
The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow local users to obtain sensitive information.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | 2.4.0 – 2.4.35.2 | — |
| linux | linux_kernel | >= 2.6.0 < 2.6.24 | 2.6.24 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_real_time_extension | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_ubuntu4.0MEDIUM
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2008-02-14·CVSS 4.0
CVE-2006-7229 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
The minix filesystem did not properly validate certain filesystem
values. If a local attacker could trick the system into attempting
to mount a corrupted minix filesystem, the kernel could be made to
hang for long periods of time, resulting in a denial of service.
(CVE-2006-6058)
Alexander Schulze discovered that the skge driver does not properly
use the spin_lock and spin_unlock functions. Remote attackers could
exploit this by sending a flood of network traffic and cause a denial
of service (crash). (CVE-2006-7229)
Hugh Dickins discovered that hugetlbfs performed certain prio_tree
calculations using HPAGE_SIZE instead of PAGE_SIZE. A local user
could exploit this and cause a denial of service via kernel panic.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2008-02-04·CVSS 4.0
CVE-2006-6058 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
The minix filesystem did not properly validate certain filesystem
values. If a local attacker could trick the system into attempting
to mount a corrupted minix filesystem, the kernel could be made to
hang for long periods of time, resulting in a denial of service.
This was only vulnerable in Ubuntu 7.04 and 7.10. (CVE-2006-6058)
The signal handling on PowerPC systems using HTX allowed local users
to cause a denial of service via floating point corruption. This was
only vulnerable in Ubuntu 6.10 and 7.04. (CVE-2007-3107)
The Linux kernel did not properly validate the hop-by-hop IPv6
extended header. Remote attackers could send a crafted IPv6 packet
and cause a denial of service via kernel panic. This was only
vuln
Red Hat
Issue with core dump owner
vendor_redhat·2004-07-10·CVSS 2.1
CVE-2007-6206 [LOW] Issue with core dump owner
Issue with core dump owner
The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow local users to obtain sensitive information.
GHSA
GHSA-c42f-578r-22gx: The do_coredump function in fs/exec
ghsa_unreviewed·2022-05-01
CVE-2007-6206 [LOW] CWE-200 GHSA-c42f-578r-22gx: The do_coredump function in fs/exec
The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow local users to obtain sensitive information.
No detection rules found.
No public exploits indexed.
http://bugzilla.kernel.org/show_bug.cgi?id=3043http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=c46f739dd39db3b07ab5deb4e3ec81e1c04a91afhttp://lists.opensuse.org/opensuse-security-announce/2008-02/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-06/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-07/msg00002.htmlhttp://lists.vmware.com/pipermail/security-announce/2008/000023.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0055.htmlhttp://secunia.com/advisories/27908http://secunia.com/advisories/28141http://secunia.com/advisories/28643http://secunia.com/advisories/28706http://secunia.com/advisories/28748http://secunia.com/advisories/28826http://secunia.com/advisories/28889http://secunia.com/advisories/28971http://secunia.com/advisories/29058http://secunia.com/advisories/30110http://secunia.com/advisories/30818http://secunia.com/advisories/30962http://secunia.com/advisories/31246http://secunia.com/advisories/33280http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0048http://www.debian.org/security/2007/dsa-1436http://www.debian.org/security/2008/dsa-1503http://www.debian.org/security/2008/dsa-1504http://www.mandriva.com/security/advisories?name=MDVSA-2008:044http://www.mandriva.com/security/advisories?name=MDVSA-2008:086http://www.mandriva.com/security/advisories?name=MDVSA-2008:112http://www.redhat.com/support/errata/RHSA-2008-0089.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0211.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0787.htmlhttp://www.securityfocus.com/archive/1/487808/100/0/threadedhttp://www.securityfocus.com/bid/26701http://www.ubuntu.com/usn/usn-574-1http://www.ubuntu.com/usn/usn-578-1http://www.vupen.com/english/advisories/2007/4090http://www.vupen.com/english/advisories/2008/2222/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/38841https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10719http://bugzilla.kernel.org/show_bug.cgi?id=3043http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=c46f739dd39db3b07ab5deb4e3ec81e1c04a91afhttp://lists.opensuse.org/opensuse-security-announce/2008-02/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-06/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-07/msg00002.htmlhttp://lists.vmware.com/pipermail/security-announce/2008/000023.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0055.htmlhttp://secunia.com/advisories/27908http://secunia.com/advisories/28141http://secunia.com/advisories/28643http://secunia.com/advisories/28706http://secunia.com/advisories/28748http://secunia.com/advisories/28826http://secunia.com/advisories/28889http://secunia.com/advisories/28971http://secunia.com/advisories/29058http://secunia.com/advisories/30110http://secunia.com/advisories/30818http://secunia.com/advisories/30962http://secunia.com/advisories/31246http://secunia.com/advisories/33280http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0048http://www.debian.org/security/2007/dsa-1436http://www.debian.org/security/2008/dsa-1503http://www.debian.org/security/2008/dsa-1504http://www.mandriva.com/security/advisories?name=MDVSA-2008:044http://www.mandriva.com/security/advisories?name=MDVSA-2008:086http://www.mandriva.com/security/advisories?name=MDVSA-2008:112http://www.redhat.com/support/errata/RHSA-2008-0089.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0211.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0787.htmlhttp://www.securityfocus.com/archive/1/487808/100/0/threadedhttp://www.securityfocus.com/bid/26701http://www.ubuntu.com/usn/usn-574-1http://www.ubuntu.com/usn/usn-578-1http://www.vupen.com/english/advisories/2007/4090http://www.vupen.com/english/advisories/2008/2222/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/38841https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10719
2007-12-04
Published