CVE-2008-2358

Integer overflow in the dccp_feat_change function in net/dccp/feat.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.18, and 2.6.17 through 2.6.20, allows local users to gain privileges via an invalid feature length, which leads to a heap-based buffer overflow.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:2.6.17:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.18:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.19:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.20:*:*:*:*:*:*:*

History

No history.

Information

Published : 2008-06-10 00:32

Updated : 2024-02-28 11:21


NVD link : CVE-2008-2358

Mitre link : CVE-2008-2358

CVE.ORG link : CVE-2008-2358


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-189

Numeric Errors