CVE-2007-5093
Last modified
CVE-2007-5093 is a vulnerability of currently unknown severity. The disconnect method in the Philips USB Webcam (pwc) driver in Linux kernel 2.6.x before 2.6.22.6 "relies on user space to close the device," which allows user-assisted local attackers to cause a denial of service (USB subsystem hang and CPU consumption in khubd) by not closing the device after the disconnect is invoked. NOTE: this rarely crosses privilege boundaries, unless the attacker can convince the victim to unplug the affected device.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
The disconnect method in the Philips USB Webcam (pwc) driver in Linux kernel 2.6.x before 2.6.22.6 "relies on user space to close the device," which allows user-assisted local attackers to cause a denial of service (USB subsystem hang and CPU consumption in khubd) by not closing the device after the disconnect is invoked. NOTE: this rarely crosses privilege boundaries, unless the attacker can convince the victim to unplug the affected device.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | 2.6.0 | — |
| Linux | Linux Kernel | 2.6.1 | — |
| Linux | Linux Kernel | 2.6.2 | — |
| Linux | Linux Kernel | 2.6.3 | — |
| Linux | Linux Kernel | 2.6.4 | — |
| Linux | Linux Kernel | 2.6.5 | — |
| Linux | Linux Kernel | 2.6.6 | — |
| Linux | Linux Kernel | 2.6.7 | — |
| Linux | Linux Kernel | 2.6.8 | — |
| Linux | Linux Kernel | 2.6.8.1 | — |
| Linux | Linux Kernel | 2.6.8.1.5 | — |
| Linux | Linux Kernel | 2.6.9 | — |
| Linux | Linux Kernel | 2.6.10 | — |
| Linux | Linux Kernel | 2.6.11 | — |
| Linux | Linux Kernel | 2.6.11.1 | — |
| Linux | Linux Kernel | 2.6.11.2 | — |
| Linux | Linux Kernel | 2.6.11.3 | — |
| Linux | Linux Kernel | 2.6.11.4 | — |
| Linux | Linux Kernel | 2.6.11.5 | — |
| Linux | Linux Kernel | 2.6.11.6 | — |
| Linux | Linux Kernel | 2.6.11.7 | — |
| Linux | Linux Kernel | 2.6.11.8 | — |
| Linux | Linux Kernel | 2.6.11.9 | — |
| Linux | Linux Kernel | 2.6.11.10 | — |
| Linux | Linux Kernel | 2.6.11.11 | — |
| Linux | Linux Kernel | 2.6.11.12 | — |
| Linux | Linux Kernel | 2.6.11_rc1_bk6 | — |
| Linux | Linux Kernel | 2.6.12 | — |
| Linux | Linux Kernel | 2.6.12.1 | — |
| Linux | Linux Kernel | 2.6.12.2 | — |
| Linux | Linux Kernel | 2.6.12.3 | — |
| Linux | Linux Kernel | 2.6.12.4 | — |
| Linux | Linux Kernel | 2.6.12.5 | — |
| Linux | Linux Kernel | 2.6.12.6 | — |
| Linux | Linux Kernel | 2.6.12.12 | — |
| Linux | Linux Kernel | 2.6.12.22 | — |
| Linux | Linux Kernel | 2.6.13 | — |
| Linux | Linux Kernel | 2.6.13.1 | — |
| Linux | Linux Kernel | 2.6.13.2 | — |
| Linux | Linux Kernel | 2.6.13.3 | — |
| Linux | Linux Kernel | 2.6.13.4 | — |
| Linux | Linux Kernel | 2.6.13.5 | — |
| Linux | Linux Kernel | 2.6.14 | — |
| Linux | Linux Kernel | 2.6.14.1 | — |
| Linux | Linux Kernel | 2.6.14.2 | — |
| Linux | Linux Kernel | 2.6.14.3 | — |
| Linux | Linux Kernel | 2.6.14.4 | — |
| Linux | Linux Kernel | 2.6.14.5 | — |
| Linux | Linux Kernel | 2.6.15 | — |
| Linux | Linux Kernel | 2.6.15.1 | — |
Showing 50 of 122 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5093?
How severe is CVE-2007-5093?
How do I fix CVE-2007-5093?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-5087The ATM module in the Linux kernel before 2.4.35.3, when CLI…
- CVE-2007-5088Cross-site scripting (XSS) vulnerability in search/cust_bill…
- CVE-2007-5089PHP remote file inclusion vulnerability in php-inc/log.inc.p…
- CVE-2007-5090Unspecified vulnerability in IBM Rational ClearQuest (CQ), w…
- CVE-2007-5091Multiple cross-site scripting (XSS) vulnerabilities in eGrou…
- CVE-2007-5092Directory traversal vulnerability in index.php in the Dance …
- CVE-2007-5094Heap-based buffer overflow in iaspam.dll in the SMTP Server …
- CVE-2007-5095Microsoft Windows Media Player (WMP) 9 on Windows XP SP2 inv…
- CVE-2007-5096PHP remote file inclusion vulnerability in modules/webmail2/…
- CVE-2007-5097PHP remote file inclusion vulnerability in lib/classes/offl_…9.8
- CVE-2007-5098Multiple PHP remote file inclusion vulnerabilities in DFD Ca…
- CVE-2007-5099PHP remote file inclusion vulnerability in show.php in David…
Are you affected by CVE-2007-5093?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
