CVE-2008-1673 describes a critical vulnerability in the ASN.1 implementation within the Linux kernel (versions 2.4 and 2.6) and the gxsnmp package, affecting Debian Linux. This flaw, categorized as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), stems from insufficient validation of length values during ASN.1 BER data decoding. With a CVSS score of 10.0, this vulnerability allows unauthenticated remote attackers to trigger a denial of service (crash) or execute arbitrary code due to various overflow conditions, including oversized lengths, zero-length OIDs, or indefinite lengths for primitive encodings. Despite its maximum severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting it is not currently a high-profile threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:4.0:*:alpha:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:4.0:*:amd64:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:4.0:*:arm:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:4.0:*:hppa:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.