Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-5396
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-5396

Description:
Array index error in the (1) torisa.c and (2) dahdi/tor2.c drivers in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group to overwrite an integer value in kernel memory by writing to /dev/zap/ctl, related to missing validation of the sync field associated with the ZT_SPANCONFIG ioctl.

CVE Status:
Candidate

References:

SAID
  Secunia Advisory: SA32947
  Secunia Advisory: SA32960

MLIST
  http://www.openwall.com/lists/oss-security/2008/12/03/10

CONFIRM
  http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507459
  http://bugs.digium.com/view.php?id=13954


Return to the previous page.