CVE-2008-2812

Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 09 Jul 2008, 00:00
Last modified:07 Aug 2024, 09:14

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.8 HIGH
v3.1 (nvd)
EPSS Score
0.1% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Jul 2008, 00:00
Published
Vulnerability first disclosed
07 Aug 2024, 09:14
Last Modified
Vulnerability information updated

Description

The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4) ppp_async.c, (5) ppp_synctty.c, (6) slip.c, (7) wan/x25_asy.c, and (8) wireless/strip.c in drivers/net/.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 0.10% Percentile: 27%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • avayacommunication_manager

    ≥ 3.1

  • avayaintuity_audix_lx

    2.0

  • avayameeting_exchange

    5.0

  • avayamessage_networking

    3.1

  • avayamessaging_storage_server

    4.0

  • avayaproactive_contact

    4.0

  • avayasip_enablement_services

    na | 4.0

  • canonicalubuntu_linux

    6.06 | 7.04 | 7.10 | 8.04

  • debiandebian_linux

    4.0

  • linuxlinux_kernel

    < 2.6.25.10

  • novelllinux_desktop

    9

  • opensuseopensuse

    10.3 | 11.0

  • susesuse_linux_enterprise_desktop

    10:sp1 | 10:sp2

  • susesuse_linux_enterprise_server

    10:sp1 | 10:sp2

References (33)