CVE-2008-2926

The kmxfw.sys driver in CA Host-Based Intrusion Prevention System (HIPS) r8, as used in CA Internet Security Suite and Personal Firewall, does not properly verify IOCTL requests, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted request.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:broadcom:internet_security_suite:3.0:*:*:*:*:*:*:*
cpe:2.3:a:ca:host_based_intrusion_prevention_system:r8:*:*:*:*:*:*:*
cpe:2.3:a:ca:internet_security_suite_2008:*:*:*:*:*:*:*:*
cpe:2.3:a:ca:personal_firewall_2007:*:*:*:*:*:*:*:*
cpe:2.3:a:ca:personal_firewall_2008:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:48

Type Values Removed Values Added
References () http://secunia.com/advisories/31434 - Patch, Vendor Advisory () http://secunia.com/advisories/31434 - Patch, Vendor Advisory
References () http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=36559 - () http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=36559 -
References () http://www.securityfocus.com/archive/1/495397/100/0/threaded - () http://www.securityfocus.com/archive/1/495397/100/0/threaded -
References () http://www.securityfocus.com/bid/30651 - () http://www.securityfocus.com/bid/30651 -
References () http://www.securitytracker.com/id?1020658 - () http://www.securitytracker.com/id?1020658 -
References () http://www.securitytracker.com/id?1020659 - () http://www.securitytracker.com/id?1020659 -
References () http://www.securitytracker.com/id?1020660 - () http://www.securitytracker.com/id?1020660 -
References () http://www.vupen.com/english/advisories/2008/2339 - () http://www.vupen.com/english/advisories/2008/2339 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/44392 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/44392 -

Information

Published : 2008-08-12 23:41

Updated : 2024-11-21 00:48


NVD link : CVE-2008-2926

Mitre link : CVE-2008-2926

CVE.ORG link : CVE-2008-2926


JSON object : View

Products Affected

ca

  • host_based_intrusion_prevention_system
  • internet_security_suite_2008
  • personal_firewall_2007
  • personal_firewall_2008

broadcom

  • internet_security_suite
CWE
CWE-20

Improper Input Validation