PT-2008-6866 · Linux Foundation · Linux
Publicado
1970-01-01
·
Atualizado
2012-10-30
·
CVE-2008-4445
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
linux-image-2.6.24-etchnhalf.1-sb1-bcm91250a version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-s390-tape version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-all-ia64 version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-parisc-smp version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-itanium version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-r5k-cobalt version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-iop32x version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-amd64 version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-parisc64 version 2.6.24-etchnhalf.1
linux-manual-2.6.24 version 2.6.24
linux-headers-2.6.24-etchnhalf.1-all-amd64 version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-sparc64-smp version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-alpha-smp version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-686 version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-amd64 version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-sparc64 version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-powerpc version 2.6.24-etchnhalf.1
linux-doc-2.6.24 version 2.6.24
linux-support-2.6.24-etchnhalf.1 version 2.6.24-etchnhalf.1
linux-source-2.6.24 version 2.6.24
linux-headers-2.6.24-etchnhalf.1-powerpc-miboot version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-alpha-legacy version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-powerpc-smp version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-powerpc64 version 2.6.24-etchnhalf.1
kernel-rt version not specified
linux-image-2.6.24-etchnhalf.1-alpha-generic version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-all-arm version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-parisc64-smp version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-footbridge version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-all-i386 version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-all-sparc version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-footbridge version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-powerpc-miboot version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-alpha-legacy version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-686-bigmem version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-parisc64 version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-s390 version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-powerpc64 version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-parisc-smp version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-mckinley version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-sparc64-smp version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-486 version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-sb1-bcm91250a version 2.6.24-etchnhalf.1
linux-patch-debian-2.6.24 version 2.6.24
linux-tree-2.6.24 version 2.6.24
linux-headers-2.6.24-etchnhalf.1-sparc64 version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-r5k-cobalt version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-parisc version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-powerpc-smp version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-all-alpha version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-sb1a-bcm91480b version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-486 version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-all-hppa version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-686 version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-all-powerpc version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-sb1a-bcm91480b version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-powerpc version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-ixp4xx version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-iop32x version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-4kc-malta version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-686-bigmem version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-common version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-s390x version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-alpha-smp version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-all-mipsel version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-all-s390 version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-s390 version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-5kc-malta version 2.6.24-etchnhalf.1
kernel-rt debug version not specified
linux-headers-2.6.24-etchnhalf.1-ixp4xx version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-itanium version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-mckinley version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-parisc version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-alpha-generic version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-all version 2.6.24-etchnhalf.1
linux-image-2.6.24-etchnhalf.1-5kc-malta version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-parisc64-smp version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-s390x version 2.6.24-etchnhalf.1
linux-headers-2.6.24-etchnhalf.1-4kc-malta version 2.6.24-etchnhalf.1
Description
The issue affects the Linux kernel and can lead to a disruption of confidentiality, integrity, and availability of protected information. Exploitation of the vulnerabilities can be done remotely. The sctp auth ep set hmacs function in net/sctp/auth.c does not verify that the identifier index is within the bounds established by SCTP AUTH HMAC ID MAX, allowing local users to obtain sensitive information via a crafted SCTP HMAC IDENT IOCTL request involving the sctp getsockopt function.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux