Vulnerability Name: | CVE-2007-4774 (CCN-177160) | ||||||||||||||||
Assigned: | 2007-09-10 | ||||||||||||||||
Published: | 2020-01-15 | ||||||||||||||||
Updated: | 2020-02-04 | ||||||||||||||||
Summary: | The Linux kernel before 2.4.36-rc1 has a race condition. It was possible to bypass systrace policies by flooding the ptraced process with SIGCONT signals, which can can wake up a PTRACED process. | ||||||||||||||||
CVSS v3 Severity: | 5.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N) 5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||||||||||
Vulnerability Type: | CWE-362 | ||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2007-4774 Source: MISC Type: Third Party Advisory http://taviso.decsystem.org/research.html Source: XF Type: UNKNOWN linux-kernel-cve20074774-sec-bypass(177160) Source: MISC Type: Issue Tracking, Third Party Advisory https://osdn.net/projects/linux-kernel-docs/scm/git/linux-2.4.36/listCommit?skip=60 Source: CCN Type: NetApp Advisory Number NTAP-20200204-0002 January 2020 Linux Kernel Vulnerabilities in NetApp Products Source: CONFIRM Type: UNKNOWN https://security.netapp.com/advisory/ntap-20200204-0002/ Source: CCN Type: Linux Kernel Web site The Linux Kernel Archives | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |