7.2
CVSSv2

CVE-2008-2358

Published: 10/06/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer overflow in the dccp_feat_change function in net/dccp/feat.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.18, and 2.6.17 up to and including 2.6.20, allows local users to gain privileges via an invalid feature length, which leads to a heap-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 2.6.17

linux linux kernel 2.6.19

linux linux kernel 2.6.18

linux linux kernel 2.6.20

Vendor Advisories

Dirk Nehring discovered that the IPsec protocol stack did not correctly handle fragmented ESP packets A remote attacker could exploit this to crash the system, leading to a denial of service (CVE-2007-6282) ...
Two vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or arbitrary code execution The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-1673 Wei Wang from McAfee reported a potential heap overflow in the ASN1 decode code that is used by the SNMP NAT and CI ...