>> Linux Kernel Local Privilege Escalation and Denial of Service Vulnerabilities
Title : Linux Kernel Local Privilege Escalation and Denial of Service Vulnerabilities VUPEN ID : VUPEN/ADV-2007-3246 CVE ID : CVE-2007-4573 - CVE-2007-5087
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2007-09-24
Technical Description
Two vulnerabilities have been identified in Linux Kernel, which could be exploited by local attackers to cause a denial of service or gain elevated privileges.
The first issue is caused due to certain x86_64 registers not being zero-extended after ptrace in the 32bit entry path, which could be exploited by malicious users to obtain elevated privileges.
The second vulnerability is caused by an error in the ATM module when loaded with CLIP support while the CLIP module is not loaded yet, which could be exploited by malicious users to panic a vulnerable system, creating a denial of service condition.