[openbsd-security-announce] 20080111 errata 005 for OpenBSD 4.2: local users can provoke a kernel panicmailing list
http://marc.info/?l=openbsd-security-announce&m=120007327504064 CVE-2008-0384
OpenBSD 4.2 - 'rtlabel_id2name()' Local Null Pointer Dereference Denial of Service
Record summary
CVE-2008-0384 has a selected CVSS score of 4.9; EIP currently links 1 catalogued exploit.
Description
OpenBSD 4.2 allows local users to cause a denial of service (kernel panic) by calling the SIOCGIFRTLABEL IOCTL on an interface that does not have a route label, which triggers a NULL pointer dereference when the return value from the rtlabel_id2name function is not checked.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOpenBSD 4.2 - 'rtlabel_id2name()' Local Null Pointer Dereference Denial of ServiceExploitDB exploitby HungerNot analyzed1 file
References
728473Third-party advisory
http://secunia.com/advisories/28473 [4.2] 20080111 005: RELIABILITY FIX: January 11, 2008Vendor advisory
http://www.openbsd.org/errata42.html 27252vdb entry
http://www.securityfocus.com/bid/27252 1019188vdb entry
http://www.securitytracker.com/id?1019188 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-0384 4935exploit
https://www.exploit-db.com/exploits/4935