PT-2008-2017 · Openbsd · Openbsd
Hunger
·
Published
2008-01-22
·
Updated
2018-10-30
·
CVE-2008-0384
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
OpenBSD version 4.2
Description
The issue allows local users to cause a denial of service, resulting in a kernel panic. This occurs when the SIOCGIFRTLABEL IOCTL is called on an interface without a route label, leading to a NULL pointer dereference. The problem arises because the return value from the
rtlabel id2name function is not properly checked.Recommendations
For OpenBSD version 4.2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openbsd