Vulnerability Name:

CVE-2007-1523 (CCN-33463)

Assigned:2007-01-29
Published:2007-01-29
Updated:2013-08-28
Summary:Heap-based buffer overflow in the kernel in NetBSD 3.0, certain versions of FreeBSD and OpenBSD, and possibly other BSD derived operating systems allows local users to have an unknown impact.
Note: this information is based upon a vague pre-advisory with no actionable information. Details will be updated after 20070329.
CVSS v3 Severity:4.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
6.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
3.7 Low (CCN CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2007-1523

Source: CCN
Type: Kernel Wars Blog, Monday, January 29, 2007
Kernel Wars

Source: MISC
Type: Vendor Advisory
http://kernelwars.blogspot.com/2007/01/alive.html

Source: OSVDB
Type: UNKNOWN
34593

Source: MISC
Type: Vendor Advisory
http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#Eriksson

Source: CCN
Type: The NetBSD Project Web site
The NetBSD Project

Source: CCN
Type: OSVDB ID: 34593
Multiple BSD Unspecified Kernel Overflow

Source: BID
Type: UNKNOWN
22945

Source: CCN
Type: BID-22945
NetBSD Kernel Unspecified Local Buffer Overflow Vulnerability

Source: XF
Type: UNKNOWN
netbsd-unspecified-bo(33463)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:netbsd:netbsd:3.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:netbsd:netbsd:3.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    netbsd netbsd 3.0
    netbsd netbsd 3.0