CVE-2008-3915

NameCVE-2008-3915
DescriptionBuffer overflow in nfsd in the Linux kernel before 2.6.26.4, when NFSv4 is enabled, allows remote attackers to have an unknown impact via vectors related to decoding an NFSv4 acl.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-1636-1
NVD severityhigh (attack range: remote)
Debian/oldoldstablenot vulnerable.
Debian/oldstablenot known to be vulnerable.
Debian/stablenot known to be vulnerable.
Debian/testingnot known to be vulnerable.
Debian/unstablenot known to be vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux-2.6 (PTS)squeeze, squeeze (security)2.6.32-48squeeze6fixed
squeeze (lts)2.6.32-48squeeze11fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linux-2.6source(unstable)2.6.26-5high
linux-2.6sourceetch(not affected)
linux-2.6.24source(unstable)2.6.24-6~etchnhalf.5high
linux-2.6.24sourceetch2.6.24-6~etchnhalf.5highDSA-1636-1

Notes

[etch] - linux-2.6 <not-affected> (Vulnerable code was introduced in 2.6.19)
91b80969ba466ba4b915a4a1d03add8c297add3f

Search for package or bug name: Reporting problems