Sploitus

CVE-2008-0600

4 known exploits for CVE-2008-0600

The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer before dereference, which allows local users to gain root privileges via crafted arguments in a vmsplice system call, a different vulnerability than CVE-2008-0009 and CVE-2008-0010.

Linux Linux Kernel
= 2.6.17, 2.6.17.1, 2.6.17.2, 2.6.17.3, 2.6.17.4, 2.6.17.5, 2.6.17.6, 2.6.17.7, 2.6.17.8, 2.6.17.9, 2.6.17.10, 2.6.17.11, 2.6.17.12, 2.6.17.13, 2.6.17.14, 2.6.18, 2.6.18.1, 2.6.18.2, 2.6.18.3, 2.6.18.4, 2.6.18.5, 2.6.18.6, 2.6.18.7, 2.6.18.8, 2.6.19, 2.6.19.1, 2.6.19.2, 2.6.19.3, 2.6.20, 2.6.20.1, 2.6.20.2, 2.6.20.3, 2.6.20.4, 2.6.20.5, 2.6.20.6, 2.6.20.7, 2.6.20.8, 2.6.20.9, 2.6.20.10, 2.6.20.11
Fix
Available
CVSS 2.0
7.2 HIGH
EPSS
3.5% (88th percentile)
Weakness
CWE-94
NVD status
Modified
Published
2008-02-12
CVE-2008-0600 at NVD
Authoritative description, scoring and affected products

4 known exploits for CVE-2008-0600

Proof-of-concept code and exploit modules indexed by Sploitus