>> Linux Kernel ASN.1 BER Decoding Remote Buffer Overflow Vulnerability
Title : Linux Kernel ASN.1 BER Decoding Remote Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2008-1770 CVE ID : CVE-2008-1673 CWE ID : CWE-119
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-06-09
Technical Description
A vulnerability has been identified in Linux Kernel, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error in the ASN.1 decoder of the CIFS filesytem [fs/cifs/asn1.c] and the Basic SNMP Application Layer Gateway [net/ipv4/netfilter/nf_nat_snmp_basic.c] modules when processing specially crafted BER data, which could be exploited by remote attackers to crash an affected system or execute arbitrary code with elevated privileges via malicious BER packets.