CVE-2007-5093

medium

Description

The disconnect method in the Philips USB Webcam (pwc) driver in Linux kernel 2.6.x before 2.6.22.6 "relies on user space to close the device," which allows user-assisted local attackers to cause a denial of service (USB subsystem hang and CPU consumption in khubd) by not closing the device after the disconnect is invoked. NOTE: this rarely crosses privilege boundaries, unless the attacker can convince the victim to unplug the affected device.

References

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10494

https://euvd.enisa.europa.eu/vulnerability/EUVD-2007-5074

http://www.ubuntu.com/usn/usn-578-1

http://www.ubuntu.com/usn/usn-574-1

http://www.ubuntu.com/usn/usn-558-1

http://www.securityfocus.com/bid/25504

http://www.redhat.com/support/errata/RHSA-2008-0275.html

http://www.mandriva.com/security/advisories?name=MDVSA-2008:105

http://www.mandriva.com/security/advisories?name=MDVSA-2008:008

http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.6

http://www.debian.org/security/2008/dsa-1504

http://www.debian.org/security/2008/dsa-1503

http://www.debian.org/security/2007/dsa-1381

http://secunia.com/advisories/32799

http://secunia.com/advisories/30294

http://secunia.com/advisories/29058

http://secunia.com/advisories/28971

http://secunia.com/advisories/28706

http://secunia.com/advisories/28170

http://secunia.com/advisories/26994

http://rhn.redhat.com/errata/RHSA-2008-0972.html

http://marc.info/?l=linux-kernel&m=118880154122548&w=2

http://marc.info/?l=linux-kernel&m=118873457814808&w=2

Details

Source: Mitre, NVD

Published: 2007-09-26

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:L/AC:H/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00091