CVE-2008-5033

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The chip_command function in drivers/media/video/tvaudio.c in the Linux kernel 2.6.25.x before 2.6.25.19, 2.6.26.x before 2.6.26.7, and 2.6.27.x before 2.6.27.3 allows attackers to cause a denial of service (NULL function pointer dereference and OOPS) via unknown vectors.

References

http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=5ba2f67afb02c5302b2898949ed6fc3b3d37dcf1

http://secunia.com/advisories/32918

http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.19

http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.26.7

http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.3

http://www.mandriva.com/security/advisories?name=MDVSA-2008:246

http://www.securityfocus.com/bid/32094

http://www.ubuntu.com/usn/usn-679-1

https://exchange.xforce.ibmcloud.com/vulnerabilities/46544

Details

Source: MITRE

Published: 2008-11-10

Updated: 2017-08-08

Type: CWE-399

Risk Information

CVSS v2

Base Score: 7.8

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Impact Score: 6.9

Exploitability Score: 10

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:linux:linux_kernel:2.6.25:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.1:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.2:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.3:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.4:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.5:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.6:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.7:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.8:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.9:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.10:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.11:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.12:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.13:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.14:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.15:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.16:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.17:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.25.18:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.26:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.26.1:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.26.2:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.26.3:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.26.4:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.26.5:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.26.6:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.27:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.27.1:*:*:*:*:*:*:*

cpe:2.3:o:linux:linux_kernel:2.6.27.2:*:*:*:*:*:*:*

Tenable Plugins

View all (3 total)

IDNameProductFamilySeverity
40783openSUSE Security Update : kernel (kernel-1211)NessusSuSE Local Security Checks
high
37874Mandriva Linux Security Advisory : kernel (MDVSA-2008:246)NessusMandriva Local Security Checks
high
37683Ubuntu 6.06 LTS / 7.10 / 8.04 LTS / 8.10 : linux, linux-source-2.6.15/22 vulnerabilities (USN-679-1)NessusUbuntu Local Security Checks
high