Vulnerability Description
Linux kernel 2.2.1 through 2.2.19, and 2.4.1 through 2.4.10, allows local users to cause a denial of service via a series of deeply nested symlinks, which causes the kernel to spend extra time when trying to access the link.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 2.2.1, <= 2.2.19 |
References
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2001-036.0.txtBroken Link
- http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-035-01Broken Link
- http://frontal2.mandriva.com/security/advisories?name=MDKSA-2001:079Third Party Advisory
- http://marc.info/?l=bugtraq&m=100343090106914&w=2Mailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=100350685431610&w=2Mailing ListThird Party Advisory
- http://www.iss.net/security_center/static/7312.phpBroken Link
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-082.php3Broken Link
- http://www.linuxsecurity.com/advisories/other_advisory-1650.htmlThird Party Advisory
- http://www.novell.com/linux/security/advisories/2001_036_kernel_txt.htmlBroken Link
- http://www.securityfocus.com/bid/3444Third Party AdvisoryVDB Entry
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2001-036.0.txtBroken Link
- http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-035-01Broken Link
- http://frontal2.mandriva.com/security/advisories?name=MDKSA-2001:079Third Party Advisory
- http://marc.info/?l=bugtraq&m=100343090106914&w=2Mailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=100350685431610&w=2Mailing ListThird Party Advisory
FAQ
What is CVE-2001-0907?
CVE-2001-0907 is a vulnerability with a CVSS score of 2.1 (LOW). Linux kernel 2.2.1 through 2.2.19, and 2.4.1 through 2.4.10, allows local users to cause a denial of service via a series of deeply nested symlinks, which causes the kernel to spend extra time when tr...
How severe is CVE-2001-0907?
CVE-2001-0907 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-0907?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.