CVE-2008-5744
Array index error in the dahdi/tor2.c driver in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group to overwrite an integer value in kernel memory by writing to /dev/zap/ctl, related to an incorrect tor2 patch for CVE-2008-5396…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.47%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Array index error in the dahdi/tor2.c driver in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group to overwrite an integer value in kernel memory by writing to /dev/zap/ctl, related to an incorrect tor2 patch for CVE-2008-5396 that uses the wrong variable in a range check against the value of lc->sync.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.47% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- asterisk/zaptel
- Source
- cve@mitre.org
References
- http://bugs.digium.com/view.php?id=13954#96700
- http://secunia.com/advisories/32960
- http://svn.digium.com/view/dahdi?view=rev&revision=5590
- http://www.openwall.com/lists/oss-security/2008/12/19/2Exploit
- https://bugzilla.redhat.com/show_bug.cgi?id=475446#c4
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47666
- http://bugs.digium.com/view.php?id=13954#96700
- http://secunia.com/advisories/32960
- http://svn.digium.com/view/dahdi?view=rev&revision=5590
- http://www.openwall.com/lists/oss-security/2008/12/19/2Exploit
- https://bugzilla.redhat.com/show_bug.cgi?id=475446#c4
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47666
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.