CVE-2008-0384
Estado: ModificadaMedia (4.9)—💥 Exploit
OpenBSD 4.2 allows local users to cause a denial of service (kernel panic) by calling the SIOCGIFRTLABEL IOCTL on an interface that does not have a route label, which triggers a NULL pointer dereference when the return value from the rtlabel_id2name function is not checked.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C
- Puntuación base: 4.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.85%
- Percentil entre todas las CVEs puntuadas: 57
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Publicado en Exploit-DB · OpenBSD 4.2 - 'rtlabel_id2name()' Local Null Pointer Dereference Denial of Service (18/1/2008)
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://marc.info/?l=openbsd-security-announce&m=120007327504064
- http://secunia.com/advisories/28473
- http://www.openbsd.org/errata42.html#005_ifrtlabel
- http://www.securityfocus.com/bid/27252
- http://www.securitytracker.com/id?1019188
- https://www.exploit-db.com/exploits/4935
- http://marc.info/?l=openbsd-security-announce&m=120007327504064
- http://secunia.com/advisories/28473
- http://www.openbsd.org/errata42.html#005_ifrtlabel
- http://www.securityfocus.com/bid/27252
- http://www.securitytracker.com/id?1019188
- https://www.exploit-db.com/exploits/4935
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-0384",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.9,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:N/I:N/A:C",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-01-22T20:00:00.000",
"references": [
{
"url": "http://marc.info/?l=openbsd-security-announce&m=120007327504064",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/28473",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.openbsd.org/errata42.html#005_ifrtlabel",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/27252",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1019188",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/4935",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=openbsd-security-announce&m=120007327504064",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/28473",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openbsd.org/errata42.html#005_ifrtlabel",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/27252",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1019188",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/4935",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "OpenBSD 4.2 allows local users to cause a denial of service (kernel panic) by calling the SIOCGIFRTLABEL IOCTL on an interface that does not have a route label, which triggers a NULL pointer dereference when the return value from the rtlabel_id2name function is not checked."
},
{
"lang": "es",
"value": "OpenBSD 4.2 permtie a usuarios locales provocar denegación de servicio (kernel panic) a través de una llamada SIOCGIFRTLABEL IOCTL sobre una interfaz que no tiene una etiqueta route, el cual dispara un puntero de referencia NULL cuando devuelve el valor de la función rtlabel_id2name no está validada."
}
],
"lastModified": "2026-06-16T22:49:30.563",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:openbsd:openbsd:4.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9DF8DD37-A337-4E9D-A34E-C2D561A24285"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}