« Volver al listado

CVE-2008-0976

Estado: ModificadaMedia (5)—

Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed packet, as demonstrated by a packet of type (1) 0x2722 or (2) 0x272a.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-0976",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-02-25T23:44:00.000",
  "references": [
    {
      "url": "http://aluigi.altervista.org/adv/doubletakedown-adv.txt",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://aluigi.org/poc/doubletakedown.zip",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/29075",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/3698",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/488632/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/27951",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/0666",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://aluigi.altervista.org/adv/doubletakedown-adv.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://aluigi.org/poc/doubletakedown.zip",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/29075",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/3698",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/488632/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/27951",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/0666",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-399"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed packet, as demonstrated by a packet of type (1) 0x2722 or (2) 0x272a."
    },
    {
      "lang": "es",
      "value": "Double-Take 5.0.0.2865 y anteriores, distribuido con el nombre de HP StorageWorks Storage Mirroring y otros nombres, permite a atacantes remotos provocar una denegación de  servicio (referencia a puntero nulo o caída del demonio) a través de un paquete mal formado, como se demostró por un paquete de los tipos (1) 0x2722 o (2) 0x272a."
    }
  ],
  "lastModified": "2026-06-16T22:50:43.083",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:double-take_software:double-take:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7CAE56F4-BE8E-4C4D-8FEE-BCBC85151427",
              "versionEndIncluding": "5.0.0.2865"
            },
            {
              "criteria": "cpe:2.3:a:double-take_software:double-take:4.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F178F692-773F-4D8A-BA9C-78D448126649"
            },
            {
              "criteria": "cpe:2.3:a:hp:storageworks_double-take:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "774A4ECB-35CC-4D62-815E-55B5D25670C1",
              "versionEndIncluding": "5.0.0.2865"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "vendorComments": [
    {
      "comment": "This issue was fixed in version 5.1 which was released July  11, 2008\n",
      "lastModified": "2009-05-08T00:00:00",
      "organization": "Double-Take"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}