CVE-2008-2358
kernel: dccp: sanity check feature length
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Integer overflow in the dccp_feat_change function in net/dccp/feat.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.18, and 2.6.17 through 2.6.20, allows local users to gain privileges via an invalid feature length, which leads to a heap-based buffer overflow.
Un desbordamiento de enteros en la función dccp_feat_change en el archivo net/dccp/feat.c en el subsistema Datagram Congestion Control Protocol (DCCP) en el kernel de Linux versión 2.6.18, y versiones 2.6.17 hasta 2.6.20, permite a los usuarios locales alcanzar privilegios por medio de una longitud de funcionalidad no válida, lo que conlleva a un desbordamiento de búfer en la región heap de la memoria.
Two vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or arbitrary code execution. Wei Wang from McAfee reported a potential heap overflow in the ASN.1 decode code that is used by the SNMP NAT and CIFS subsystem. Exploitation of this issue may lead to arbitrary code execution. This issue is not believed to be exploitable with the pre-built kernel images provided by Debian, but it might be an issue for custom images built from the Debian-provided source package. Brandon Edwards of McAfee Avert labs discovered an issue in the DCCP subsystem. Due to missing feature length checks it is possible to cause an overflow they may result in remote arbitrary code execution. This updated advisory adds the linux-2.6 build for mipsel which was not yet available at the time of DSA-1592-1.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-05-21 CVE Reserved
- 2008-06-09 CVE Published
- 2024-08-07 CVE Updated
- 2025-04-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-189: Numeric Errors
CAPEC
References (18)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/29603 | Vdb Entry | |
http://www.securitytracker.com/id?1020211 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/43034 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9644 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00006.html | 2017-09-29 | |
http://secunia.com/advisories/30000 | 2017-09-29 | |
http://secunia.com/advisories/30818 | 2017-09-29 | |
http://secunia.com/advisories/30849 | 2017-09-29 | |
http://secunia.com/advisories/30920 | 2017-09-29 | |
http://secunia.com/advisories/31107 | 2017-09-29 | |
http://www.debian.org/security/2008/dsa-1592 | 2017-09-29 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2008:112 | 2017-09-29 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2008:167 | 2017-09-29 | |
http://www.redhat.com/support/errata/RHSA-2008-0519.html | 2017-09-29 | |
http://www.ubuntu.com/usn/usn-625-1 | 2017-09-29 | |
https://bugzilla.redhat.com/show_bug.cgi?id=447389 | 2008-06-25 | |
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00082.html | 2017-09-29 | |
https://access.redhat.com/security/cve/CVE-2008-2358 | 2008-06-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 2.6.17 Search vendor "Linux" for product "Linux Kernel" and version "2.6.17" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 2.6.18 Search vendor "Linux" for product "Linux Kernel" and version "2.6.18" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 2.6.19 Search vendor "Linux" for product "Linux Kernel" and version "2.6.19" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 2.6.20 Search vendor "Linux" for product "Linux Kernel" and version "2.6.20" | - |
Affected
|