CVE-2008-0384
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/01/2008
Last modified:
09/04/2025
Description
OpenBSD 4.2 allows local users to cause a denial of service (kernel panic) by calling the SIOCGIFRTLABEL IOCTL on an interface that does not have a route label, which triggers a NULL pointer dereference when the return value from the rtlabel_id2name function is not checked.
Impact
Base Score 2.0
4.90
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:openbsd:openbsd:4.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://marc.info/?l=openbsd-security-announce&m=120007327504064
- http://secunia.com/advisories/28473
- http://www.openbsd.org/errata42.html#005_ifrtlabel
- http://www.securityfocus.com/bid/27252
- http://www.securitytracker.com/id?1019188=
- https://www.exploit-db.com/exploits/4935
- http://marc.info/?l=openbsd-security-announce&m=120007327504064
- http://secunia.com/advisories/28473
- http://www.openbsd.org/errata42.html#005_ifrtlabel
- http://www.securityfocus.com/bid/27252
- http://www.securitytracker.com/id?1019188=
- https://www.exploit-db.com/exploits/4935