7.8

CVE-2008-2812

The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4) ppp_async.c, (5) ppp_synctty.c, (6) slip.c, (7) wan/x25_asy.c, and (8) wireless/strip.c in drivers/net/.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version < 2.6.25.10
CanonicalUbuntu Linux Version6.06 SwEditionlts
CanonicalUbuntu Linux Version7.04
CanonicalUbuntu Linux Version7.10
CanonicalUbuntu Linux Version8.04 SwEditionlts
NovellLinux Desktop Version9
OpensuseOpensuse Version10.3
OpensuseOpensuse Version11.0
SuseSuse Linux Enterprise Desktop Version10 Updatesp1
SuseSuse Linux Enterprise Desktop Version10 Updatesp2
SuseSuse Linux Enterprise Server Version10 Updatesp1
SuseSuse Linux Enterprise Server Version10 Updatesp2
DebianDebian Linux Version4.0
AvayaCommunication Manager Version >= 3.1
AvayaIntuity Audix Lx Version2.0
AvayaMeeting Exchange Version5.0
AvayaMessage Networking Version3.1
AvayaProactive Contact Version4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.136
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

http://www.openwall.com/lists/oss-security/2008/07/03/2
Patch
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/30076
Patch
Third Party Advisory
VDB Entry
https://usn.ubuntu.com/637-1/
Third Party Advisory