CVE-2008-5396: High severity asterisk vulnerability
Array index error in the (1) torisa.c and (2) dahdi/tor2.c drivers in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group to overwrite an integer value in kernel memory by writing to /dev/zap/ctl, related to missing validation of the sync field associated with the ZTSPANCONFIG ioctl.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5396?
CVE-2008-5396 has a high severity rating due to its potential for local users to overwrite kernel memory.
How do I fix CVE-2008-5396?
To fix CVE-2008-5396, users should upgrade to Zaptel versions later than 1.4.11 that contain the necessary patches.
Which software is affected by CVE-2008-5396?
CVE-2008-5396 affects Zaptel versions 1.4.11 and earlier, including specific versions such as 1.2 and 1.4.
What types of attacks can CVE-2008-5396 enable?
CVE-2008-5396 can enable local privilege escalation attacks due to improper validation leading to kernel memory corruption.
Who can exploit CVE-2008-5396?
Local users in the dialout group can exploit CVE-2008-5396 if they have access to the affected Zaptel driver.