>> Linux Audit "audit_log_user_command()" Buffer Overflow Vulnerability
Title : Linux Audit "audit_log_user_command()" Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2008-1052 CVE ID : CVE-2008-1628
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-01
Technical Description
A vulnerability has been identified in Linux Audit, which could be exploited by attackers to cause a denial of service or compromise an affected system. This issue is caused by a buffer overflow error in the "audit_log_user_command()" function when handling a large number of arguments, which could be exploited by attackers to crash an affected application or execute arbitrary code.