CVE

Id
29265  
CVE No.
CVE-2007-5908  
Status
Candidate  
Description
** REJECT ** Buffer overflow in the (1) sysfs_show_available_clocksources and (2) sysfs_show_current_clocksources functions in Linux kernel 2.6.23 and earlier might allow local users to cause a denial of service or execute arbitrary code via crafted clock source names. NOTE: follow-on analysis by Linux developers states that "There is no way for unprivileged users (or really even the root user) to add new clocksources."  
Phase
Assigned (20071109)  
Votes
None (candidate not yet proposed)  
Comments