CVE-2007-2480
MediumThe _udp_lib_get_port function in net/ipv4/udp.c in Linux kernel 2.6.21 and earlier does not prevent a bind to a port with a local address when there is already a bind to that port with a wildcard local address, which might allow local users to intercept local traffic for daemons or other applications.
CVSS 2.0 score
4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P
References
The following references provide additional information about CVE-2007-2480 including vendor advisories, patch commits, exploit details, and third-party analysis. Links are sourced from the NIST NVD database.
Frequently asked questions
-
What is CVE-2007-2480?
CVE-2007-2480 is a Medium severity Linux kernel vulnerability with a CVSS score of 4.6 out of 10 . CVE-2007-2480 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
What is the CVSS score for CVE-2007-2480?
CVE-2007-2480 has a CVSS score of 4.6 out of 10, rated Medium severity (CVSS 2.0). The vector string is
AV:L/AC:L/Au:N/C:P/I:P/A:P. -
Is there a patch available for CVE-2007-2480?
No patch is currently available for CVE-2007-2480. Monitor the NIST NVD and your Linux distribution's security advisories for updates.
-
Is CVE-2007-2480 actively exploited?
No — CVE-2007-2480 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.