3.6
CVSSv2

CVE-2008-2148

Published: 12/05/2008 Updated: 07/11/2023
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

The utimensat system call (sys_utimensat) in Linux kernel 2.6.22 and other versions prior to 2.6.25.3 does not check file permissions when certain UTIME_NOW and UTIME_OMIT combinations are used, which allows local users to modify file times of arbitrary files, possibly leading to a denial of service.

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 2.6.22.15

linux linux kernel 2.6.22.4

linux linux kernel 2.6.22.21

linux linux kernel 2.6.22.12

linux linux kernel 2.6.22.1

linux linux kernel 2.6.22

linux linux kernel 2.6.22.7

linux linux kernel 2.6.22.18

linux linux kernel 2.6.22.20

linux linux kernel 2.6.22.6

linux linux kernel 2.6.22.3

linux linux kernel 2.6.22.9

linux linux kernel 2.6.22.13

linux linux kernel 2.6.22.17

linux linux kernel 2.6.22.11

linux linux kernel 2.6.22.10

linux linux kernel 2.6.22.8

linux linux kernel 2.6.22.2

linux linux kernel 2.6.22.19

linux linux kernel 2.6.22.5

linux linux kernel 2.6.22.16

linux linux kernel 2.6.22.14

Vendor Advisories

Dirk Nehring discovered that the IPsec protocol stack did not correctly handle fragmented ESP packets A remote attacker could exploit this to crash the system, leading to a denial of service (CVE-2007-6282) ...