CVE-2008-4395Improper Restriction of Operations within the Bounds of a Memory Buffer in Linux Kernel

Severity
8.3HIGHNVD
EPSS
3.0%
top 13.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 6
Latest updateMay 2

Description

Multiple buffer overflows in the ndiswrapper module 1.53 for the Linux kernel 2.6 allow remote attackers to execute arbitrary code by sending packets over a local wireless network that specify long ESSIDs.

CVSS vector

AV:A/AC:L/C:C/I:C/A:CExploitability: 6.5 | Impact: 10.0

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
GHSA-cfmc-g2m2-7ffx: Multiple buffer overflows in the ndiswrapper module 12022-05-02
CVEList
CVE-2008-4395: Multiple buffer overflows in the ndiswrapper module 12008-11-06
OSV
CVE-2008-4395: Multiple buffer overflows in the ndiswrapper module 12008-11-06

📋Vendor Advisories

3
Ubuntu
Ubuntu kernel modules vulnerability2008-11-06
Ubuntu
Linux kernel vulnerabilities2008-11-05
Red Hat
CVE-2008-4395: Multiple buffer overflows in the ndiswrapper module 1
CVE-2008-4395 — Ubuntu Linux Kernel vulnerability | cvebase