Security Advisory

CVE-2008-1673

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2008-06-10 00:00:00
Last updated 2024-08-07 08:32:01
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

The asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6 before 2.6.25.5, as used in the cifs and ip_nat_snmp_basic modules; and (b) the gxsnmp package; does not properly validate length values during decoding of ASN.1 BER data, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a length greater than the working buffer, which can lead to an unspecified overflow; (2) an oid length of zero, which can lead to an off-by-one error; or (3) an indefinite length for a primitive encoding.