CVE-2007-6206 describes a sensitive information disclosure vulnerability in the Linux kernel's do_coredump function (fs/exec.c), affecting versions 2.4.x and 2.6.x up to 2.6.24-rc3, including distributions like Canonical, Debian, and Red Hat. The flaw allows local users to potentially access sensitive data if a core dump file pre-exists and a root process subsequently creates a core dump in the same location without changing the file's UID. This vulnerability has a low severity, rated with a CVSS score of 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N), indicating local access is required, and its primary impact is limited to confidentiality. The EPSS score is very low, suggesting a minimal likelihood of exploitation. There is no evidence of active exploitation, and no public exploit code exists on platforms like Metasploit or ExploitDB. The CVE has received no community discussion or media coverage, further indicating a lack of widespread attention or exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4.0, <= 2.4.35.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 2.6.0, < 2.6.24CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
2.6.24CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.24:-:*:*:*:*:*:* | ||
2.6.24CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.24:rc1:*:*:*:*:*:* | ||
2.6.24CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.24:rc2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.