CVE-2008-1675
Last modified
CVE-2008-1675 is a vulnerability of currently unknown severity. The bdx_ioctl_priv function in the tehuti driver (tehuti.c) in Linux kernel 2.6.x before 2.6.25.1 does not properly check certain information related to register size, which has unspecified impact and local attack vectors, probably related to reading or writing kernel memory.. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
The bdx_ioctl_priv function in the tehuti driver (tehuti.c) in Linux kernel 2.6.x before 2.6.25.1 does not properly check certain information related to register size, which has unspecified impact and local attack vectors, probably related to reading or writing kernel memory.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | 2.6.0 |
| Linux | Linux Kernel | 2.6.1 |
| Linux | Linux Kernel | 2.6.2 |
| Linux | Linux Kernel | 2.6.10 |
| Linux | Linux Kernel | 2.6.11 |
| Linux | Linux Kernel | 2.6.11.1 |
| Linux | Linux Kernel | 2.6.11.2 |
| Linux | Linux Kernel | 2.6.11.3 |
| Linux | Linux Kernel | 2.6.11.4 |
| Linux | Linux Kernel | 2.6.11.5 |
| Linux | Linux Kernel | 2.6.11.6 |
| Linux | Linux Kernel | 2.6.11.7 |
| Linux | Linux Kernel | 2.6.11.8 |
| Linux | Linux Kernel | 2.6.11.9 |
| Linux | Linux Kernel | 2.6.11.10 |
| Linux | Linux Kernel | 2.6.11.11 |
| Linux | Linux Kernel | 2.6.11.12 |
| Linux | Linux Kernel | 2.6.12 |
| Linux | Linux Kernel | 2.6.12.1 |
| Linux | Linux Kernel | 2.6.12.2 |
| Linux | Linux Kernel | 2.6.12.3 |
| Linux | Linux Kernel | 2.6.12.4 |
| Linux | Linux Kernel | 2.6.12.5 |
| Linux | Linux Kernel | 2.6.12.6 |
| Linux | Linux Kernel | 2.6.13 |
| Linux | Linux Kernel | 2.6.13.1 |
| Linux | Linux Kernel | 2.6.13.2 |
| Linux | Linux Kernel | 2.6.13.3 |
| Linux | Linux Kernel | 2.6.13.4 |
| Linux | Linux Kernel | 2.6.13.5 |
| Linux | Linux Kernel | 2.6.14 |
| Linux | Linux Kernel | 2.6.14.1 |
| Linux | Linux Kernel | 2.6.14.2 |
| Linux | Linux Kernel | 2.6.14.3 |
| Linux | Linux Kernel | 2.6.14.4 |
| Linux | Linux Kernel | 2.6.14.5 |
| Linux | Linux Kernel | 2.6.14.6 |
| Linux | Linux Kernel | 2.6.14.7 |
| Linux | Linux Kernel | 2.6.15 |
| Linux | Linux Kernel | 2.6.15.1 |
| Linux | Linux Kernel | 2.6.15.2 |
| Linux | Linux Kernel | 2.6.15.3 |
| Linux | Linux Kernel | 2.6.15.4 |
| Linux | Linux Kernel | 2.6.15.5 |
| Linux | Linux Kernel | 2.6.15.6 |
| Linux | Linux Kernel | 2.6.15.7 |
| Linux | Linux Kernel | 2.6.16 |
| Linux | Linux Kernel | 2.6.16.1 |
| Linux | Linux Kernel | 2.6.16.2 |
| Linux | Linux Kernel | 2.6.16.3 |
Showing 50 of 221 affected configurations. See NVD for the full list.
References
- http://secunia.com/advisories/30017Vendor Advisory
- http://secunia.com/advisories/30044Vendor Advisory
- http://secunia.com/advisories/30260Vendor Advisory
- http://secunia.com/advisories/30515Vendor Advisory
- http://www.vupen.com/english/advisories/2008/1406/referencesVendor Advisory
- http://secunia.com/advisories/30017Vendor Advisory
- http://secunia.com/advisories/30044Vendor Advisory
- http://secunia.com/advisories/30260Vendor Advisory
- http://secunia.com/advisories/30515Vendor Advisory
- http://www.vupen.com/english/advisories/2008/1406/referencesVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-1675?
How severe is CVE-2008-1675?
How do I fix CVE-2008-1675?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-1669Linux kernel before 2.6.25.2 does not apply a certain protec…
- CVE-2008-1670Heap-based buffer overflow in the progressive PNG Image load…
- CVE-2008-1671start_kdeinit in KDE 3.5.5 through 3.5.9, when installed set…
- CVE-2008-1672OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a…
- CVE-2008-1673The asn1 implementation in (a) the Linux kernel 2.4 before 2…
- CVE-2008-1674Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2008-1676Red Hat PKI Common Framework (rhpki-common) in Red Hat Certi…
- CVE-2008-1677Buffer overflow in the regular expression handler in Red Hat…
- CVE-2008-1678Memory leak in the zlib_stateful_init function in crypto/com…
- CVE-2008-1679Multiple integer overflows in imageop.c in Python before 2.5…
- CVE-2008-1680PHP-Nuke Platinum 7.6.b.5 allows remote attackers to obtain …
- CVE-2008-1681Unspecified vulnerability in IBM DB2 Content Manager before …
Are you affected by CVE-2008-1675?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
