Buffer overflow in the (1) sysfs_show_available_clocksources and (2) sysfs_show_current_clocksources functions in Linux kernel 2.6.23 and earlier might allow local users to cause a denial of service or execute arbitrary code via crafted clock source names. NOTE: follow-on analysis by Linux developers states that "There is no way for unprivileged users (or really even the root user) to add new clocksources.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: REJECTED
Assigner: mitre
Published: 2007-11-09T19:00:00
Updated: 2007-11-28T10:00:00
Reserved: 2007-11-09T00:00:00
Link: CVE-2007-5908
Vulnrichment
No data.
NVD
Status : Rejected
Published: 2007-11-09T19:46:00.000
Modified: 2023-11-07T02:01:24.240
Link: CVE-2007-5908
Redhat