imPC@ndo IT

Tracker / CVE-2008-2812

CVE-2008-2812

High 7.8

The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4) ppp_async.c, (5) ppp_synctty.c, (6) slip.c, (7) wan/x25_asy.c, and (8) wireless/strip.c in drivers/net/.

Affected products and versions

avaya communication_manager · 3.1 → …
avaya expanded_meet-me_conferencing
avaya intuity_audix_lx
avaya meeting_exchange
avaya message_networking
avaya messaging_storage_server
avaya proactive_contact
avaya sip_enablement_services
canonical ubuntu_linux
debian debian_linux
linux linux_kernel · … → 2.6.25.10
novell linux_desktop
opensuse opensuse
suse suse_linux_enterprise_desktop
suse suse_linux_enterprise_server

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References