{ "id": "CVE-2007-0253", "sourceIdentifier": "cve@mitre.org", "published": "2007-01-16T23:28:00.000", "lastModified": "2024-11-21T00:25:21.663", "vulnStatus": "Modified", "cveTags": [ { "sourceIdentifier": "cve@mitre.org", "tags": [ "disputed" ] } ], "descriptions": [ { "lang": "en", "value": "Unspecified vulnerability in the grsecurity patch has unspecified impact and remote attack vectors, a different vulnerability than the expand_stack vulnerability from the Digital Armaments 20070110 pre-advisory. NOTE: the grsecurity developer has disputed this issue, stating that \"the function they claim the vulnerability to be in is a trivial function, which can, and has been, easily checked for any supposed vulnerabilities.\" The developer also cites a past disclosure that was not proven" }, { "lang": "es", "value": "** EN DISPUTA ** La vulnerabilidad no especificada en el parche grsecurity tiene un impacto no especificado y vectores de ataque remoto, una vulnerabilidad diferente a la vulnerabilidad expand_stack del pre-asesor Digital Armaments 20070110. NOTA: el desarrollador de grsecurity ha impugnado este problema, afirmando que \"la funci\u00f3n en la que afirman que est\u00e1 la vulnerabilidad es una funci\u00f3n trivial, que puede, y ha sido, f\u00e1cilmente comprobada por cualquier supuesta vulnerabilidad\". El desarrollador tambi\u00e9n cita una divulgaci\u00f3n anterior que no fue probada." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C", "baseScore": 7.2, "accessVector": "LOCAL", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "availabilityImpact": "COMPLETE" }, "baseSeverity": "HIGH", "exploitabilityScore": 3.9, "impactScore": 10.0, "acInsufInfo": false, "obtainAllPrivilege": true, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:grsecurity:grsecurity_kernel_patch:*:*:*:*:*:*:*:*", "matchCriteriaId": "C6C337DA-7715-4BBB-A537-F240CF04F36C" } ] } ] } ], "references": [ { "url": "http://forums.grsecurity.net/viewtopic.php?t=1646", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] }, { "url": "http://grsecurity.net/news.php#digitalfud", "source": "cve@mitre.org" }, { "url": "http://www.digitalarmaments.com/news_news.shtml", "source": "cve@mitre.org", "tags": [ "Vendor Advisory", "URL Repurposed" ] }, { "url": "http://forums.grsecurity.net/viewtopic.php?t=1646", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://grsecurity.net/news.php#digitalfud", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.digitalarmaments.com/news_news.shtml", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory", "URL Repurposed" ] } ] }