CVE Database
/

CVE-2008-2710

Back to search

CVE-2008-2710

Published: Jun 16, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Integer signedness error in the ip_set_srcfilter function in the IP Multicast Filter in uts/common/inet/ip/ip_multi.c in the kernel in Sun Solaris 10 and OpenSolaris before snv_92 allows local users to execute arbitrary code in other Solaris Zones via an SIOCSIPMSFILTER IOCTL request with a large value of the imsf->imsf_numsrc field, which triggers an out-of-bounds write of kernel memory. NOTE: this was reported as an integer overflow, but the root cause involves the bypass of a signed comparison.

VendorProductVersions

n/a

n/a

affected
n/a

References

oval:org.mitre.oval:def:5731
vdb-entry
signature
x_refsource_OVAL
237965
vendor-advisory
x_refsource_SUNALERT
ADV-2008-1832
vdb-entry
x_refsource_VUPEN
29699
vdb-entry
x_refsource_BID
30693
third-party-advisory
x_refsource_SECUNIA
1020283
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now