PT-2008-6968 · Opensuse+2 · Opensuse+2

Eugene Teo

·

Publicado

1970-01-01

·

Atualizado

2017-08-08

·

CVE-2008-4410

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions openSUSE kernel-rt debug (affected versions not specified) openSUSE kernel-rt (affected versions not specified) Linux kernel version 2.6.26.5
Description The issue involves multiple vulnerabilities in the kernel-rt and kernel-rt debug packages of the openSUSE operating system, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. Additionally, a specific vulnerability in the Linux kernel version 2.6.26.5 allows local users to cause a denial of service via crafted function calls, related to improper LDT selector state in the Java Runtime Environment.
Recommendations For openSUSE kernel-rt debug, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For openSUSE kernel-rt, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Linux kernel version 2.6.26.5, consider restricting access to the vmi write ldt entry function in arch/x86/kernel/vmi 32.c to minimize the risk of exploitation.

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-05034
BDU:2015-05035
CVE-2008-4410

Produtos afetados

Java Runtime Environment
Linux Kernel
Opensuse