CVE Reference: CVE-2007-1353

NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-1353

Description:
The setsockopt function in the L2CAP and HCI Bluetooth support in the Linux kernel before 2.4.34.3 allows context-dependent attackers to read kernel memory and obtain sensitive information via unspecified vectors involving the copy_from_user function accessing an uninitialized stack buffer.

CVE Status:
Candidate

References:

UBUNTU
  http://www.ubuntu.com/usn/usn-486-1
  http://www.ubuntu.com/usn/usn-489-1
  http://www.ubuntu.com/usn/usn-470-1

SUSE
  http://www.novell.com/linux/security/advisories/2007_35_kernel.html

SAID
  Secunia Advisory: SA26133
  Secunia Advisory: SA25838
  Secunia Advisory: SA25683
  Secunia Advisory: SA25700
  Secunia Advisory: SA24976
  Secunia Advisory: SA25596
  Secunia Advisory: SA26139
  Secunia Advisory: SA26289
  Secunia Advisory: SA26379
  Secunia Advisory: SA26478
  Secunia Advisory: SA26450
  Secunia Advisory: SA27528
  Secunia Advisory: SA29058

REDHAT
  http://www.redhat.com/support/errata/RHSA-2007-0671.html
  http://www.redhat.com/support/errata/RHSA-2007-0672.html
  http://www.redhat.com/support/errata/RHSA-2007-0673.html
  http://rhn.redhat.com/errata/RHSA-2007-0488.html

OVAL
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10626

DEBIAN
  http://www.debian.org/security/2007/dsa-1356
  http://www.debian.org/security/2008/dsa-1503
  http://www.debian.org/security/2008/dsa-1504

CONFIRM
  http://support.avaya.com/elmodocs2/security/ASA-2007-404.htm
  http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm
  http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.34.3

BID
  23594


Return to the previous page.