// For flags

CVE-2007-0005

Linux Omnikey Cardman 4040 Driver - Local Buffer Overflow (PoC)

Severity Score

7.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple buffer overflows in the (1) read and (2) write handlers in the Omnikey CardMan 4040 driver in the Linux kernel before 2.6.21-rc3 allow local users to gain privileges.

MĂșltiples desbordamientos de bĂșfer en los manejadores de (1) lectura y (2) escritura en el controlador Omnikey CardMan 4040 en el kernel de Linux versiones anteriores a 2.6.21-rc3, permite a usuarios locales alcanzar privilegios.

The compat_sys_mount function allowed local users to cause a denial of service when mounting a smbfs filesystem in compatibility mode. The Omnikey CardMan 4040 driver (cm4040_cs) did not limit the size of buffers passed to read() and write(). A local attacker could exploit this to execute arbitrary code with kernel privileges. Due to a variable handling flaw in the ipv6_getsockopt_sticky() function a local attacker could exploit the getsockopt() calls to read arbitrary kernel memory. This could disclose sensitive data. Ilja van Sprundel discovered that Bluetooth setsockopt calls could leak kernel memory contents via an uninitialized stack buffer. A local attacker could exploit this flaw to view sensitive kernel information. A flaw was discovered in the handling of netlink messages. Local attackers could cause infinite recursion leading to a denial of service. A flaw was discovered in the IPv6 stack's handling of type 0 route headers. By sending a specially crafted IPv6 packet, a remote attacker could cause a denial of service between two IPv6 hosts. The random number generator was hashing a subset of the available entropy, leading to slightly less random numbers. Additionally, systems without an entropy source would be seeded with the same inputs at boot time, leading to a repeatable series of random numbers. A flaw was discovered in the PPP over Ethernet implementation. Local attackers could manipulate ioctls and cause kernel memory consumption leading to a denial of service. An integer underflow was discovered in the cpuset filesystem. If mounted, local attackers could obtain kernel memory using large file offsets while reading the tasks file. This could disclose sensitive data. Vilmos Nebehaj discovered that the SCTP netfilter code did not correctly validate certain states. A remote attacker could send a specially crafted packet causing a denial of service. Luca Tettamanti discovered a flaw in the VFAT compat ioctls on 64-bit systems. A local attacker could corrupt a kernel_dirent struct and cause a denial of service.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-12-19 CVE Reserved
  • 2007-03-09 First Exploit
  • 2007-03-10 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (28)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Omnikey.aaitg
Search vendor "Omnikey.aaitg"
Omnikey Cardman 4040
Search vendor "Omnikey.aaitg" for product "Omnikey Cardman 4040"
*-
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
<= 2.6.21
Search vendor "Linux" for product "Linux Kernel" and version " <= 2.6.21"
rc2
Safe
Omnikey.aaitg
Search vendor "Omnikey.aaitg"
Omnikey Cardman 4040
Search vendor "Omnikey.aaitg" for product "Omnikey Cardman 4040"
*-
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.21
Search vendor "Linux" for product "Linux Kernel" and version "2.6.21"
-
Safe
Omnikey.aaitg
Search vendor "Omnikey.aaitg"
Omnikey Cardman 4040
Search vendor "Omnikey.aaitg" for product "Omnikey Cardman 4040"
*-
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.21
Search vendor "Linux" for product "Linux Kernel" and version "2.6.21"
rc1
Safe
Omnikey.aaitg
Search vendor "Omnikey.aaitg"
Omnikey Cardman 4040
Search vendor "Omnikey.aaitg" for product "Omnikey Cardman 4040"
*-
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.21.1
Search vendor "Linux" for product "Linux Kernel" and version "2.6.21.1"
-
Safe
Omnikey.aaitg
Search vendor "Omnikey.aaitg"
Omnikey Cardman 4040
Search vendor "Omnikey.aaitg" for product "Omnikey Cardman 4040"
*-
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.21.2
Search vendor "Linux" for product "Linux Kernel" and version "2.6.21.2"
-
Safe
Omnikey.aaitg
Search vendor "Omnikey.aaitg"
Omnikey Cardman 4040
Search vendor "Omnikey.aaitg" for product "Omnikey Cardman 4040"
*-
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.21.3
Search vendor "Linux" for product "Linux Kernel" and version "2.6.21.3"
-
Safe
Omnikey.aaitg
Search vendor "Omnikey.aaitg"
Omnikey Cardman 4040
Search vendor "Omnikey.aaitg" for product "Omnikey Cardman 4040"
*-
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.21.4
Search vendor "Linux" for product "Linux Kernel" and version "2.6.21.4"
-
Safe
Omnikey.aaitg
Search vendor "Omnikey.aaitg"
Omnikey Cardman 4040
Search vendor "Omnikey.aaitg" for product "Omnikey Cardman 4040"
*-
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.21.5
Search vendor "Linux" for product "Linux Kernel" and version "2.6.21.5"
-
Safe
Omnikey.aaitg
Search vendor "Omnikey.aaitg"
Omnikey Cardman 4040
Search vendor "Omnikey.aaitg" for product "Omnikey Cardman 4040"
*-
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.21.6
Search vendor "Linux" for product "Linux Kernel" and version "2.6.21.6"
-
Safe
Omnikey.aaitg
Search vendor "Omnikey.aaitg"
Omnikey Cardman 4040
Search vendor "Omnikey.aaitg" for product "Omnikey Cardman 4040"
*-
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
2.6.21.7
Search vendor "Linux" for product "Linux Kernel" and version "2.6.21.7"
-
Safe