MEDIUM · 6.6

CVE-2007-1730

Integer signedness error in the DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later allows local users to read kernel memory or cause a denial of servi...

Vulnerability Description

Integer signedness error in the DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later allows local users to read kernel memory or cause a denial of service (oops) via a negative optlen value.

CVSS Score

6.6

MEDIUM

AV:L/AC:L/Au:N/C:C/I:N/A:C
Confidentiality
COMPLETE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
LinuxLinux Kernel2.6.20

References

FAQ

What is CVE-2007-1730?

CVE-2007-1730 is a vulnerability with a CVSS score of 6.6 (MEDIUM). Integer signedness error in the DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later allows local users to read kernel memory or cause a denial of servi...

How severe is CVE-2007-1730?

CVE-2007-1730 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-1730?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.