7.2

CVE-2008-2358

Integer overflow in the dccp_feat_change function in net/dccp/feat.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.18, and 2.6.17 through 2.6.20, allows local users to gain privileges via an invalid feature length, which leads to a heap-based buffer overflow.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version2.6.17
LinuxLinux Kernel Version2.6.18
LinuxLinux Kernel Version2.6.19
LinuxLinux Kernel Version2.6.20
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.41% 0.329
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.mandriva.com/security/advisories?name=MDVSA-2008:112
http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00006.html
http://secunia.com/advisories/30818
Vendor Advisory
http://secunia.com/advisories/31107
Vendor Advisory
http://www.ubuntu.com/usn/usn-625-1
http://www.mandriva.com/security/advisories?name=MDVSA-2008:167
http://secunia.com/advisories/30000
Vendor Advisory
http://www.debian.org/security/2008/dsa-1592
http://secunia.com/advisories/30849
Vendor Advisory
http://secunia.com/advisories/30920
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-0519.html
http://www.securityfocus.com/bid/29603
http://www.securitytracker.com/id?1020211
https://bugzilla.redhat.com/show_bug.cgi?id=447389
https://exchange.xforce.ibmcloud.com/vulnerabilities/43034
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9644
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00082.html