CVE-2007-4573HighConfirmedExploit available
DEB
DEB
Debian Security Advisories (DSA)
DSAs are published by the Debian Security Team for issues affecting the stable distribution. The downstream tracker (security-tracker.debian.org) additionally maps every CVE to its package-level status across all supported suites.
Region
Intl.
Updates
1 ч
License
Public Domain
Advisories covering the Debian stable and oldstable releases. Ship notes include the exact .deb version that remediates each issue.
https://www.debian.org/security/ →Share link
Anyone with the link can open this vulnerability.
The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does…
CVSS
7.2
High
EPSS
0.00
p63
Published
2007-01-01
Updated
2007-01-01
Description
The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to gain privileges by triggering an out-of-bounds access to the system call table using the %RAX register.
Tags · CWE
LPE
CWE-264
CWE-264CategoryObsolete
Permissions, Privileges, and Access Controls
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
https://cwe.mitre.org/data/definitions/264.html →Open in CWE collection →Affected products
Linux_kernel ≤ 2.4.35Linux_kernel ≤ 2.6.22.6
CVSS vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Timeline
2007-01-01
Published
2007-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: C
Complete
Integrity Impact
I: C
Complete
Availability Impact
A: C
Complete
Exploit indicators
EPSS
0.004 · p63
Known exploited (KEV)
No
Known exploits — Сканер-ВС
30080
exploitdb · https://www.exploit-db.com/exploits/30080
30604
exploitdb · https://www.exploit-db.com/exploits/30604
30605
exploitdb · https://www.exploit-db.com/exploits/30605
4460
exploitdb · https://www.exploit-db.com/exploits/4460
6851
exploitdb · https://www.exploit-db.com/exploits/6851
7618
exploitdb · https://www.exploit-db.com/exploits/7618
CVE-2006-4814
github-poc · https://github.com/tagatac/linux-CVE-2006-4814
Affected software
| Product | Vendor | Status |
|---|---|---|
| kernel | Tracked | |
| kernel | Tracked | |
| kernel | Tracked | |
| linux | Tracked | |
| linux-2.6 | Tracked | |
| linux_kernel | * | Tracked |
Source databases
DEB
DEB
Debian Security Advisories (DSA)
DSAs are published by the Debian Security Team for issues affecting the stable distribution. The downstream tracker (security-tracker.debian.org) additionally maps every CVE to its package-level status across all supported suites.
Region
Intl.
Updates
1 ч
License
Public Domain
Advisories covering the Debian stable and oldstable releases. Ship notes include the exact .deb version that remediates each issue.
https://www.debian.org/security/ →CVE
CVE
National Vulnerability Database
NVD is the U.S. government repository of standards-based vulnerability management data, built on top of the MITRE CVE list. Every record includes CPE applicability statements, CVSS v2 and v3.x base scores, CWE mappings and cross-references to advisories.
Region
US
Updates
15 min
License
Public Domain
Comprehensive catalog of publicly disclosed vulnerabilities with CPE matches, CVSS scoring and reference URLs. De-facto standard for cross-vendor correlation.
https://nvd.nist.gov →RED
RED
Red Hat Security Advisories (RHSA)
Red Hat advisories are authoritative for RHEL-family systems: each record lists the exact package NEVRA fixed, the affected streams, and a Red Hat-assigned severity that may differ from NVD's. Many downstream projects (CentOS Stream, Rocky, Alma) follow these IDs.
Region
US
Updates
1 ч
License
CC BY-SA 4.0
Advisories for Red Hat Enterprise Linux, OpenShift, Ansible and other Red Hat products. Includes detailed backport tracking — critical for long-term-support distributions.
https://access.redhat.com/security/security-updates/ →UBU
UBU
Ubuntu Security Notices (USN)
USNs are authoritative for Ubuntu systems. The CVE Tracker links each vulnerability to its per-release status (needed, released, not-affected) and to the exact Launchpad bug where the fix is integrated.
Region
Intl.
Updates
1 ч
License
CC BY-SA 3.0
Security notices for Ubuntu LTS and interim releases, covering main, universe and (via Pro) ESM-extended packages.
https://ubuntu.com/security/notices →Related vulnerabilities
BDU:2015-01615BDU:2015-01616BDU:2015-01617BDU:2015-01618BDU:2015-01619BDU:2015-01620BDU:2015-01621BDU:2015-01622BDU:2015-01623BDU:2015-01624BDU:2015-01625BDU:2015-01626BDU:2015-01627BDU:2015-01628BDU:2015-01629BDU:2015-01630BDU:2015-01631BDU:2015-01632BDU:2015-01633BDU:2015-01634BDU:2015-01635BDU:2015-01636BDU:2015-01637BDU:2015-01638BDU:2015-01639BDU:2015-01640BDU:2015-01641BDU:2015-01642BDU:2015-01643BDU:2015-01644BDU:2015-01645BDU:2015-01646BDU:2015-01647BDU:2015-01648BDU:2015-01649BDU:2015-01650BDU:2015-01651BDU:2015-01652BDU:2015-01653BDU:2015-01654BDU:2015-01655BDU:2015-01656BDU:2015-01657BDU:2015-01658BDU:2015-01659BDU:2015-01660BDU:2015-01661BDU:2015-01662BDU:2015-01663BDU:2015-01664BDU:2015-01665BDU:2015-01666BDU:2015-01667BDU:2015-01668BDU:2015-01669BDU:2015-01670BDU:2015-01671BDU:2015-01672BDU:2015-01673BDU:2015-01674BDU:2015-01675BDU:2015-01676BDU:2015-01677BDU:2015-01678BDU:2015-01679BDU:2015-01680BDU:2015-01681BDU:2015-01682BDU:2015-01683BDU:2015-01684BDU:2015-01685BDU:2015-01686BDU:2015-01687BDU:2015-01688BDU:2015-01689BDU:2015-01690BDU:2015-01691BDU:2015-01692BDU:2015-01693BDU:2015-01694BDU:2015-01695BDU:2015-01696BDU:2015-01697BDU:2015-01698BDU:2015-01699BDU:2015-01700BDU:2015-01701BDU:2015-01702BDU:2015-01703BDU:2015-01704BDU:2015-01705BDU:2015-01706BDU:2015-01707BDU:2015-01708BDU:2015-01709BDU:2015-01710BDU:2015-01711BDU:2015-01712BDU:2015-01713BDU:2015-01714BDU:2015-01715BDU:2015-01716BDU:2015-01717BDU:2015-01718BDU:2015-01719BDU:2015-01720BDU:2015-01721BDU:2015-01722BDU:2015-01723BDU:2015-01724BDU:2015-01725BDU:2015-01726BDU:2015-01727BDU:2015-01728BDU:2015-01729BDU:2015-01730BDU:2015-01731BDU:2015-01732BDU:2015-01733BDU:2015-01734BDU:2015-02148BDU:2015-04220BDU:2015-04221BDU:2015-04222BDU:2015-04223BDU:2015-04224BDU:2015-04225BDU:2015-04898BDU:2015-04899BDU:2015-04900BDU:2015-04901BDU:2015-04902BDU:2015-04903BDU:2015-04904BDU:2015-04905BDU:2015-04906BDU:2015-04907BDU:2015-04908BDU:2015-04909BDU:2015-04910BDU:2015-04911BDU:2015-04912BDU:2015-04913BDU:2015-04914BDU:2015-04915BDU:2015-04916BDU:2015-04917