HIGH · 7.8

CVE-2008-2812

The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL ...

Vulnerability Description

The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4) ppp_async.c, (5) ppp_synctty.c, (6) slip.c, (7) wan/x25_asy.c, and (8) wireless/strip.c in drivers/net/.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LinuxLinux Kernel< 2.6.25.10
CanonicalUbuntu Linux6.06
NovellLinux Desktop9
OpensuseOpensuse10.3
SuseSuse Linux Enterprise Desktop10
SuseSuse Linux Enterprise Server10
DebianDebian Linux4.0
AvayaCommunication Manager>= 3.1
AvayaExpanded Meet-Me ConferencingAll versions
AvayaIntuity Audix Lx2.0
AvayaMeeting Exchange5.0
AvayaMessage Networking3.1
AvayaMessaging Storage Server4.0
AvayaProactive Contact4.0
AvayaSip Enablement Services-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-2812?

CVE-2008-2812 is a vulnerability with a CVSS score of 7.8 (HIGH). The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL ...

How severe is CVE-2008-2812?

CVE-2008-2812 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-2812?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Canonical Ubuntu Linux, Novell Linux Desktop, Opensuse Opensuse, Suse Suse Linux Enterprise Desktop.