|
|

CVE Reference: CVE-2008-3636 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2008-3636 |
|
|
Description: Integer overflow in the IopfCompleteRequest API in the kernel in Microsoft Windows 2000, XP, Server 2003, and Vista allows context-dependent attackers to gain privileges. NOTE: this issue was originally reported for GEARAspiWDM.sys 2.0.7.5 in Gear Software CD DVD Filter driver before 4.001.7, as used in other products including Apple iTunes and multiple Symantec and Norton products, which allows local users to gain privileges via repeated IoAttachDevice IOCTL calls to \\.\GEARAspiWDMDevice in this GEARAspiWDM.sys. However, the root cause is the integer overflow in the API call itself. |
|
|
CVE Status: Candidate |
|
|
References: ST 1020998 1020997 1020999 1020839 OVAL http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6035 MISC http://www.wintercore.com/advisories/advisory_W021008.html CONFIRM http://www.gearsoftware.com/support/GEARAspi%20Security%20Information.pdf http://securityresponse.symantec.com/avcenter/security/Content/2008.10.07a.html http://www.symantec.com/avcenter/security/Content/2008.10.07a.html http://support.apple.com/kb/HT3025 CERT-VN 146896 BUGTRAQ http://www.securityfocus.com/archive/1/archive/1/497131/100/0/threaded BID 31089 APPLE http://lists.apple.com/archives/security-announce//2008/Sep/msg00001.html |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |