>> Sun Solaris SIOCSIPMSFILTER Kernel Integer Overflow Vulnerability
Title : Sun Solaris SIOCSIPMSFILTER Kernel Integer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2008-1832 CVE ID : CVE-2008-2710 CWE ID : CWE-189
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-06-13
Technical Description
A vulnerability has been identified in Sun Solaris, which could be exploited by local attackers to cause a denial of service or gain elevated privileges. This issue is caused by an integer overflow error in the "ip_set_srcfilter()" [ip_multi.c] function when handling specially crafted SIOCSIPMSFILTER IOCTL requests, which could allow malicious unprivileged users the ability to panic the system or execute arbitrary commands with kernel privileges.