CVE-2007-5756
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/11/2007
Last modified:
09/04/2025
Description
Multiple array index errors in the bpf_filter_init function in NPF.SYS in WinPcap before 4.0.2, when run in monitor mode (aka Table Management Extensions or TME), and as used in Wireshark and possibly other products, allow local users to gain privileges via crafted IOCTL requests.
Impact
Base Score 2.0
6.90
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:winpcap:winpcap:*:*:*:*:*:*:*:* | 4.0.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=625
- http://secunia.com/advisories/27676
- http://www.securityfocus.com/bid/26409
- http://www.securitytracker.com/id?1018935=
- http://www.vupen.com/english/advisories/2007/3835
- http://www.winpcap.org/misc/changelog.htm
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38433
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=625
- http://secunia.com/advisories/27676
- http://www.securityfocus.com/bid/26409
- http://www.securitytracker.com/id?1018935=
- http://www.vupen.com/english/advisories/2007/3835
- http://www.winpcap.org/misc/changelog.htm
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38433



