Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2007-6733

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。NFSv4 implementation是其中的一个分布式文件系统协议。 Linux Kernel的fs/nfs/file.c文件中的nfs_lock函数没有正确对setgid未设置group-execute权限文件的POSIX锁定进行删除,本地用户可以通过在NSF文件系统上锁定文件,然后再更改该文件的权限,导致系统崩溃。

AI Predicted 4.4 Difficulty: Trivial EPSS 0.40% · P32

Possible ATT&CK Techniques 1 AI

T1002
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2007-6733

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The nfs_lock function in fs/nfs/file.c in the Linux kernel 2.6.9 does not properly remove POSIX locks on files that are setgid without group-execute permission, which allows local users to cause a denial of service (BUG and system crash) by locking a file on an NFS filesystem and then changing this file's permissions, a related issue to CVE-2010-0727.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux Kernel nfs_lock函数本地拒绝服务漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。NFSv4 implementation是其中的一个分布式文件系统协议。 Linux Kernel的fs/nfs/file.c文件中的nfs_lock函数没有正确对setgid未设置group-execute权限文件的POSIX锁定进行删除,本地用户可以通过在NSF文件系统上锁定文件,然后再更改该文件的权限,导致系统崩溃。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2007-6733

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2007-6733

请登录查看更多情报信息。

Vendor Advisories for CVE-2007-6733 (3)

Same Patch Batch · n/a · 2010-03-16 · 28 CVEs total

CVE-2010-0985 Joomla! com_abbrev组件目录遍历漏洞
CVE-2010-0975 PHPCityPortal 'external.php'脚本PHP远程文件包含漏洞
CVE-2010-0974 PHPCityPortal 多个SQL注入漏洞
CVE-2010-0973 Scripteverkauf phppool media Domain Verkaus和Auktions Portal 'index.php' SQL注入漏洞
CVE-2010-0972 Joomla!组件路径遍历漏洞
CVE-2010-0971 ATutor 多个跨站脚本攻击漏洞
CVE-2010-0970 PhpMyLogon 'phpmylogon.php'SQL注入漏洞
CVE-2010-0969 Nlnetlabs Unbound资源管理错误漏洞
CVE-2010-0968 Geekhelps ADMP 'bannershow.php' SQL注入漏洞
CVE-2010-0967 Geekhelps ADMP 多个目录遍历漏洞
CVE-2010-0966 Dzcp deV!L`z Clanportal 'inc/config.php'PHP远程文件包含漏洞
CVE-2010-0965 Jevci.Net Jevci Siparis Formu Scripti web根目录敏感信息泄露漏洞
CVE-2010-0964 Media-Products Eros Webkatalog 'start.php'SQL注入漏洞
CVE-2010-0963 dl Download Ticket Service 'index.php' 跨站脚本攻击漏洞
CVE-2010-0397 PHP xmlrpc扩展空指针引用拒绝服务漏洞
CVE-2010-0984 Acidcat CMS web 根目录 权限许可和访问控制漏洞
CVE-2010-0983 Utilo Rezervi 'include/mail.inc.php'脚本 PHP远程文件包含漏洞
CVE-2010-0982 Joomla!组件路径遍历漏洞
CVE-2010-0981 Joomla!SQL注入漏洞
CVE-2010-0980 Left 4 Dead Stats 'player.php'脚本 SQL注入漏洞

Showing top 20 of 28 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2007-6733

No comments yet


Leave a comment