CVE-2008-1673
Last modified
CVE-2008-1673 is a vulnerability of currently unknown severity. The asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6 before 2.6.25.5, as used in the cifs and ip_nat_snmp_basic modules; and (b) the gxsnmp package; does not properly validate length values during decoding of ASN.1 BER data, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a length greater than the working buffer, which can lead to an unspecified overflow; (2) an oid length of zero, which can lead to an off-by-one error; or (3) an indefinite length for a primitive encoding.. EPSS estimates a 7.09% chance of exploitation in the next 30 days.
Description
The asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6 before 2.6.25.5, as used in the cifs and ip_nat_snmp_basic modules; and (b) the gxsnmp package; does not properly validate length values during decoding of ASN.1 BER data, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a length greater than the working buffer, which can lead to an unspecified overflow; (2) an oid length of zero, which can lead to an off-by-one error; or (3) an indefinite length for a primitive encoding.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Debian | Debian Linux | 4.0 | — |
| Linux | Linux Kernel | 2.4.0 | — |
| Linux | Linux Kernel | 2.4.1 | — |
| Linux | Linux Kernel | 2.4.2 | — |
| Linux | Linux Kernel | 2.4.3 | — |
| Linux | Linux Kernel | 2.4.4 | — |
| Linux | Linux Kernel | 2.4.5 | — |
| Linux | Linux Kernel | 2.4.6 | — |
| Linux | Linux Kernel | 2.4.7 | — |
| Linux | Linux Kernel | 2.4.8 | — |
| Linux | Linux Kernel | 2.4.9 | — |
| Linux | Linux Kernel | 2.4.10 | — |
| Linux | Linux Kernel | 2.4.11 | — |
| Linux | Linux Kernel | 2.4.12 | — |
| Linux | Linux Kernel | 2.4.13 | — |
| Linux | Linux Kernel | 2.4.14 | — |
| Linux | Linux Kernel | 2.4.15 | — |
| Linux | Linux Kernel | 2.4.16 | — |
| Linux | Linux Kernel | 2.4.17 | — |
| Linux | Linux Kernel | 2.4.18 | — |
| Linux | Linux Kernel | 2.4.19 | — |
| Linux | Linux Kernel | 2.4.20 | — |
| Linux | Linux Kernel | 2.4.21 | — |
| Linux | Linux Kernel | 2.4.22 | — |
| Linux | Linux Kernel | 2.4.23 | — |
| Linux | Linux Kernel | 2.4.23_ow2 | — |
| Linux | Linux Kernel | 2.4.24 | — |
| Linux | Linux Kernel | 2.4.24_ow1 | — |
| Linux | Linux Kernel | 2.4.25 | — |
| Linux | Linux Kernel | 2.4.26 | — |
| Linux | Linux Kernel | 2.4.27 | — |
| Linux | Linux Kernel | 2.4.28 | — |
| Linux | Linux Kernel | 2.4.29 | — |
| Linux | Linux Kernel | 2.4.30 | — |
| Linux | Linux Kernel | 2.4.31 | — |
| Linux | Linux Kernel | 2.4.32 | — |
| Linux | Linux Kernel | 2.4.33 | — |
| Linux | Linux Kernel | 2.4.33.2 | — |
| Linux | Linux Kernel | 2.4.33.3 | — |
| Linux | Linux Kernel | 2.4.33.4 | — |
| Linux | Linux Kernel | 2.4.33.5 | — |
| Linux | Linux Kernel | 2.4.34 | — |
| Linux | Linux Kernel | 2.4.35 | — |
| Linux | Linux Kernel | 2.4.36 | — |
| Linux | Linux Kernel | 2.4.36.1 | — |
| Linux | Linux Kernel | 2.4.36.2 | — |
| Linux | Linux Kernel | 2.4.36.3 | — |
| Linux | Linux Kernel | 2.4.36.4 | — |
| Linux | Linux Kernel | 2.4.36.5 | — |
| Linux | Linux Kernel | 2.6.0 | — |
Showing 50 of 173 affected configurations. See NVD for the full list.
References
- http://secunia.com/advisories/30580Vendor Advisory
- http://secunia.com/advisories/30580Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-1673?
How severe is CVE-2008-1673?
How do I fix CVE-2008-1673?
Are you affected by CVE-2008-1673?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
