CVE-2008-2926

The kmxfw.sys driver in CA Host-Based Intrusion Prevention System (HIPS) r8, as used in CA Internet Security Suite and Personal Firewall, does not properly verify IOCTL requests, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted request.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:broadcom:internet_security_suite:3.0:*:*:*:*:*:*:*
cpe:2.3:a:ca:host_based_intrusion_prevention_system:r8:*:*:*:*:*:*:*
cpe:2.3:a:ca:internet_security_suite_2008:*:*:*:*:*:*:*:*
cpe:2.3:a:ca:personal_firewall_2007:*:*:*:*:*:*:*:*
cpe:2.3:a:ca:personal_firewall_2008:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2008-08-12 23:41

Updated : 2024-02-28 11:21


NVD link : CVE-2008-2926

Mitre link : CVE-2008-2926

CVE.ORG link : CVE-2008-2926


JSON object : View

Products Affected

ca

  • personal_firewall_2008
  • internet_security_suite_2008
  • host_based_intrusion_prevention_system
  • personal_firewall_2007

broadcom

  • internet_security_suite
CWE
CWE-20

Improper Input Validation