7.2

CVE-2008-0600

Exploit

The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer before dereference, which allows local users to gain root privileges via crafted arguments in a vmsplice system call, a different vulnerability than CVE-2008-0009 and CVE-2008-0010.

Data is provided by the National Vulnerability Database (NVD)
LinuxLinux Kernel Version2.6.17
LinuxLinux Kernel Version2.6.17 Updaterc1
LinuxLinux Kernel Version2.6.17 Updaterc2
LinuxLinux Kernel Version2.6.17 Updaterc3
LinuxLinux Kernel Version2.6.17 Updaterc4
LinuxLinux Kernel Version2.6.17 Updaterc5
LinuxLinux Kernel Version2.6.17 Updaterc6
LinuxLinux Kernel Version2.6.17.1
LinuxLinux Kernel Version2.6.17.2
LinuxLinux Kernel Version2.6.17.3
LinuxLinux Kernel Version2.6.17.4
LinuxLinux Kernel Version2.6.17.5
LinuxLinux Kernel Version2.6.17.6
LinuxLinux Kernel Version2.6.17.7
LinuxLinux Kernel Version2.6.17.8
LinuxLinux Kernel Version2.6.17.9
LinuxLinux Kernel Version2.6.17.10
LinuxLinux Kernel Version2.6.17.11
LinuxLinux Kernel Version2.6.17.12
LinuxLinux Kernel Version2.6.17.13
LinuxLinux Kernel Version2.6.17.14
LinuxLinux Kernel Version2.6.18
LinuxLinux Kernel Version2.6.18 Updaterc1
LinuxLinux Kernel Version2.6.18 Updaterc2
LinuxLinux Kernel Version2.6.18 Updaterc3
LinuxLinux Kernel Version2.6.18 Updaterc4
LinuxLinux Kernel Version2.6.18 Updaterc5
LinuxLinux Kernel Version2.6.18 Updaterc6
LinuxLinux Kernel Version2.6.18 Updaterc7
LinuxLinux Kernel Version2.6.18.1
LinuxLinux Kernel Version2.6.18.2
LinuxLinux Kernel Version2.6.18.3
LinuxLinux Kernel Version2.6.18.4
LinuxLinux Kernel Version2.6.18.5
LinuxLinux Kernel Version2.6.18.6
LinuxLinux Kernel Version2.6.18.7
LinuxLinux Kernel Version2.6.18.8
LinuxLinux Kernel Version2.6.19
LinuxLinux Kernel Version2.6.19 Updaterc1
LinuxLinux Kernel Version2.6.19 Updaterc2
LinuxLinux Kernel Version2.6.19 Updaterc3
LinuxLinux Kernel Version2.6.19 Updaterc4
LinuxLinux Kernel Version2.6.19.1
LinuxLinux Kernel Version2.6.19.2
LinuxLinux Kernel Version2.6.19.3
LinuxLinux Kernel Version2.6.20
LinuxLinux Kernel Version2.6.20 Updaterc2
LinuxLinux Kernel Version2.6.20.1
LinuxLinux Kernel Version2.6.20.2
LinuxLinux Kernel Version2.6.20.3
LinuxLinux Kernel Version2.6.20.4
LinuxLinux Kernel Version2.6.20.5
LinuxLinux Kernel Version2.6.20.6
LinuxLinux Kernel Version2.6.20.7
LinuxLinux Kernel Version2.6.20.8
LinuxLinux Kernel Version2.6.20.9
LinuxLinux Kernel Version2.6.20.10
LinuxLinux Kernel Version2.6.20.11
LinuxLinux Kernel Version2.6.20.12
LinuxLinux Kernel Version2.6.20.13
LinuxLinux Kernel Version2.6.20.14
LinuxLinux Kernel Version2.6.20.15
LinuxLinux Kernel Version2.6.21
LinuxLinux Kernel Version2.6.21 Updategit1
LinuxLinux Kernel Version2.6.21 Updategit2
LinuxLinux Kernel Version2.6.21 Updategit3
LinuxLinux Kernel Version2.6.21 Updategit4
LinuxLinux Kernel Version2.6.21 Updategit5
LinuxLinux Kernel Version2.6.21 Updategit6
LinuxLinux Kernel Version2.6.21 Updategit7
LinuxLinux Kernel Version2.6.21 Updaterc3
LinuxLinux Kernel Version2.6.21 Updaterc4
LinuxLinux Kernel Version2.6.21 Updaterc5
LinuxLinux Kernel Version2.6.21 Updaterc6
LinuxLinux Kernel Version2.6.21 Updaterc7
LinuxLinux Kernel Version2.6.21.1
LinuxLinux Kernel Version2.6.21.2
LinuxLinux Kernel Version2.6.21.3
LinuxLinux Kernel Version2.6.21.4
LinuxLinux Kernel Version2.6.22
LinuxLinux Kernel Version2.6.22 Updaterc6
LinuxLinux Kernel Version2.6.22.1
LinuxLinux Kernel Version2.6.22.3
LinuxLinux Kernel Version2.6.22.4
LinuxLinux Kernel Version2.6.22.5
LinuxLinux Kernel Version2.6.22.6
LinuxLinux Kernel Version2.6.22.7
LinuxLinux Kernel Version2.6.22.16
LinuxLinux Kernel Version2.6.23
LinuxLinux Kernel Version2.6.23 Updaterc1
LinuxLinux Kernel Version2.6.23 Updaterc2
LinuxLinux Kernel Version2.6.23.1
LinuxLinux Kernel Version2.6.23.2
LinuxLinux Kernel Version2.6.23.3
LinuxLinux Kernel Version2.6.23.4
LinuxLinux Kernel Version2.6.23.5
LinuxLinux Kernel Version2.6.23.6
LinuxLinux Kernel Version2.6.23.7
LinuxLinux Kernel Version2.6.23.9
LinuxLinux Kernel Version2.6.23.14
LinuxLinux Kernel Version2.6.24
LinuxLinux Kernel Version2.6.24 Updaterc2
LinuxLinux Kernel Version2.6.24 Updaterc3
LinuxLinux Kernel Version2.6.24.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.45% 0.626
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.