CVE-2008-3247: Buffer Overflow
Published Jul 24, 2008
·Updated
The LDT implementation in the Linux kernel 2.6.25.x before 2.6.25.11 on x8664 platforms uses an incorrect size for ldtdesc, which allows local users to cause a denial of service (system crash) or possibly gain privileges via unspecified vectors.
Affected Software
13 affected components
Linux Linux kernel=2.6.25.4
Linux Linux kernel=2.6.25.11
Linux Linux kernel=2.6.25.9
Linux Linux kernel=2.6.25.12
Linux Linux kernel=2.6.25
Linux Linux kernel=2.6.25.8
Linux Linux kernel=2.6.25.6
Linux Linux kernel=2.6.25.7
Linux Linux kernel=2.6.25.2
Linux Linux kernel=2.6.25.1
Linux Linux kernel=2.6.25.3
Linux Linux kernel=2.6.25.5
Linux Linux kernel=2.6.25.10
Remediation
Event History
Jul 24, 2008
CVE Published
via MITRE·03:18 PM
Data Sourced
via MITRE·03:18 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3247?
CVE-2008-3247 has a high severity level as it can lead to a denial of service and potentially privilege escalation.
2
How do I fix CVE-2008-3247?
To fix CVE-2008-3247, update your Linux kernel to version 2.6.25.11 or later.
3
Which versions of the Linux kernel are affected by CVE-2008-3247?
CVE-2008-3247 affects Linux kernel versions 2.6.25 to 2.6.25.10 on x86_64 platforms.
4
Can CVE-2008-3247 be exploited remotely?
CVE-2008-3247 is a local vulnerability, meaning it cannot be exploited remotely.
5
What types of attacks can result from CVE-2008-3247?
CVE-2008-3247 can cause system crashes and may allow local users to gain elevated privileges.