Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-2710 (Solaris, opensolaris)

BugsAlert Home > CVE-2008-2710 (Solaris, opensolaris)
 
 

Integer signedness error in the ip_set_srcfilter function in the IP Multicast Filter in uts/common/inet/ip/ip_multi.c in the kernel in Sun Solaris 10 and OpenSolaris before snv_92 allows local users to execute arbitrary code in other Solaris Zones via an SIOCSIPMSFILTER IOCTL request with a large value of the imsf->imsf_numsrc field, which triggers an out-of-bounds write of kernel memory. NOTE: this was reported as an integer overflow, but the root cause involves the bypass of a signed compa...




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2710

Learn more about CVE-2008-2710 (Solaris, opensolaris)
 
Tags: cve-2008-2710 solaris opensolaris

Related Items

      Symantec Mail Security Lotus 1-2-3 File Viewer Buffer Overflows

      CVE-2008-4908 (crossfire)

      Is there no MVP to answer this??

      DocuSafe "Search" SQL Injection

      Avaya Products Apache mod_proxy "date" Denial of Service

      CVE-2008-4298 (lighttpd)

      VU#878044: SNMPv3 improper HMAC validation allows authentication bypass

 

Pixel