Lucene search

K
cveMitreCVE-2008-5744
HistoryDec 26, 2008 - 9:30 p.m.

CVE-2008-5744

2008-12-2621:30:00
CWE-189
mitre
web.nvd.nist.gov
31
cve-2008-5744
array index error
dahdi
tor2.c driver
zaptel
dahdi
kernel memory
local users
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

23.7%

Array index error in the dahdi/tor2.c driver in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group to overwrite an integer value in kernel memory by writing to /dev/zap/ctl, related to an incorrect tor2 patch for CVE-2008-5396 that uses the wrong variable in a range check against the value of lc->sync.

Affected configurations

Nvd
Node
asteriskzaptelRange≀1.4.11
OR
asteriskzaptelMatch1.2
OR
asteriskzaptelMatch1.2.27
OR
asteriskzaptelMatch1.4
VendorProductVersionCPE
asteriskzaptel*cpe:2.3:a:asterisk:zaptel:*:*:*:*:*:*:*:*
asteriskzaptel1.2cpe:2.3:a:asterisk:zaptel:1.2:*:*:*:*:*:*:*
asteriskzaptel1.2.27cpe:2.3:a:asterisk:zaptel:1.2.27:*:*:*:*:*:*:*
asteriskzaptel1.4cpe:2.3:a:asterisk:zaptel:1.4:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

23.7%