CVE-2008-5396
Published Dec 9, 2008
Last updated 16 years ago
Overview
- Description
- Array index error in the (1) torisa.c and (2) dahdi/tor2.c drivers in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group to overwrite an integer value in kernel memory by writing to /dev/zap/ctl, related to missing validation of the sync field associated with the ZT_SPANCONFIG ioctl.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.2
- Impact score
- 10
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-189
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:asterisk:zaptel:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "44ADB7D9-FDFE-478E-ADD0-8978BE18D365", "versionEndIncluding": "1.4.11" }, { "criteria": "cpe:2.3:a:asterisk:zaptel:1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CC52E469-E0A0-4114-A297-862E0D6364C0" }, { "criteria": "cpe:2.3:a:asterisk:zaptel:1.2.27:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3B906772-5BF8-4C60-B2D5-822D934BABFF" }, { "criteria": "cpe:2.3:a:asterisk:zaptel:1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E8A4A878-FFDF-4A58-9254-74CD7AAEEEBF" } ], "operator": "OR" } ] } ]