>> Linux Kernel "dccp_setsockopt_change()" Integer Overflow Vulnerability
Title : Linux Kernel "dccp_setsockopt_change()" Integer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2008-2406 CVE ID : CVE-2008-3276 CWE ID : CWE-189
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-08-19
Technical Description
A vulnerability has been identified in Linux Kernel, which could be exploited by attackers to cause a denial of service or potentially compromise a vulnerable system. This issue is caused by an integer overflow error in the "dccp_setsockopt_change()" [net/dccp/proto.c] function when processing user-supplied data, which could allow attackers to panic a vulnerable system or potentially execute arbitrary code.