« Volver al listado

CVE-2007-4304

Estado: ModificadaMedia (6.2)—

CerbNG for FreeBSD 4.8 does not properly implement VM protection when attempting to prevent system call wrapper races, which allows local users to have an unknown impact related to an "incorrect write protection of pages".

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-4304",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:H/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "HIGH",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 1.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-08-13T21:17:00.000",
  "references": [
    {
      "url": "http://www.watson.org/~robert/2007woot/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.watson.org/~robert/2007woot/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "CerbNG for FreeBSD 4.8 does not properly implement VM protection when attempting to prevent system call wrapper races, which allows local users to have an unknown impact related to an \"incorrect write protection of pages\"."
    },
    {
      "lang": "es",
      "value": "CerbNG para FreeBSD 4.8 no implementa protección de la memoria virtual (VM) cuando intenta prevenir condiciones de carrera en envoltorios de llamadas al sistema, lo cual permite a usuarios locales tener impacto desconocido relacionado con una \"incorrecta protección de escritura de páginas\"."
    }
  ],
  "lastModified": "2026-06-16T22:43:46.553",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:4.8:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "441BE3A0-20F4-4972-B279-19B3DB5FA14D"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cerb:cerbng:0.1:*:freebsd:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0181B778-3BF9-41A3-BAA0-1D0259E64AE8"
            },
            {
              "criteria": "cpe:2.3:a:cerb:cerbng:0.2:*:freebsd:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F3C8CEE0-3973-4B6A-ABF1-630C56FB41E7"
            },
            {
              "criteria": "cpe:2.3:a:cerb:cerbng:0.3:*:freebsd:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D418808-847A-42D7-97B8-167790F869FD"
            },
            {
              "criteria": "cpe:2.3:a:cerb:cerbng:0.4:*:freebsd:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "54FF562D-154E-4576-BB79-467D97CA842B"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "evaluatorComment": "More information about this vulnerability can be found at: http://www.securityfocus.com/bid/25259",
  "sourceIdentifier": "cve@mitre.org"
}