Vulnerability Description
The (1) aac_cfg_open and (2) aac_compat_ioctl functions in the SCSI layer ioctl path in aacraid in the Linux kernel before 2.6.23-rc2 do not check permissions for ioctls, which might allow local users to cause a denial of service or gain privileges.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | 2.6.23 |
| Adaptec | Aacraid Controller | All versions |
References
- http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.23-rc2
- http://lists.opensuse.org/opensuse-security-announce/2007-12/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00007.html
- http://lists.vmware.com/pipermail/security-announce/2008/000005.html
- http://lkml.org/lkml/2007/7/23/195
- http://secunia.com/advisories/26322Vendor Advisory
- http://secunia.com/advisories/26643
- http://secunia.com/advisories/26647
- http://secunia.com/advisories/26651
- http://secunia.com/advisories/27212
- http://secunia.com/advisories/27322
- http://secunia.com/advisories/27436
- http://secunia.com/advisories/27747
- http://secunia.com/advisories/27912
FAQ
What is CVE-2007-4308?
CVE-2007-4308 is a vulnerability with a CVSS score of 1.9 (LOW). The (1) aac_cfg_open and (2) aac_compat_ioctl functions in the SCSI layer ioctl path in aacraid in the Linux kernel before 2.6.23-rc2 do not check permissions for ioctls, which might allow local users...
How severe is CVE-2007-4308?
CVE-2007-4308 has been rated LOW with a CVSS base score of 1.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-4308?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Adaptec Aacraid Controller.