Secunia Logo
 
CVE Reference: CVE-2008-2710
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-2710

Description:
Integer signedness error in the ip_set_srcfilter function in the IP Multicast Filter in uts/common/inet/ip/ip_multi.c in the kernel in Sun Solaris 10 and OpenSolaris before snv_92 allows local users to execute arbitrary code in other Solaris Zones via an SIOCSIPMSFILTER IOCTL request with a large value of the imsf->imsf_numsrc field, which triggers an out-of-bounds write of kernel memory. NOTE: this was reported as an integer overflow, but the root cause involves the bypass of a signed comparison.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/43068

SUNALERT
  http://sunsolve.sun.com/search/document.do?assetkey=1-26-237965-1

ST
  1020283

SAID
  Secunia Advisory: SA30693

MISC
  http://www.trapkit.de/advisories/TKADV2008-003.txt

BID
  29699


Return to the previous page.