Skip to main content

CVE-2007-3848

Severity Low
Score 1.9/10

Summary

Linux kernel 2.4.35 and other versions allows local users to send arbitrary signals to a child process that is running at higher privileges by causing a setuid-root parent process to die, which delivers an attacker-controlled parent process death signal (PR_SET_PDEATHSIG).

  • MEDIUM
  • LOCAL
  • NONE
  • NONE
  • NONE
  • PARTIAL

References

Advisory Timeline

  • Published