CVE-2008-1673
The asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6 before 2.6.25.5, as used in the cifs and ip_nat_snmp_basic modules; and (b) the gxsnmp package; does not properly validat...
Affects 2 products across 2 vendors.
Parent class for buffer-related vulnerabilities where operations exceed buffer boundaries.
Show all 12
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
This vulnerability was disclosed in 2008. A critical vulnerability affects Debian systems (CVE-2008-1673). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
BSID: BS-2008-GLOBAL-329377-C • Model: rule-based-v1 • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2008-1673?
What is the CVSS score for CVE-2008-1673?
Is CVE-2008-1673 actively exploited?
How do I remediate CVE-2008-1673?
What systems are affected by CVE-2008-1673?
| CVE ID | CVE-2008-1673 |
|---|---|
| BSID | BS-2008-GLOBAL-329377-C BreachSpider Global ID |
| CVSS Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| Published | 2008-06-10 |
| Last Modified | 2026-04-23 |
| ICS Relevance | 15% |
| Weakness (CWE) | |
| Source | NVD |
The asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6 before 2.6.25.5, as used in the cifs and ip_nat_snmp_basic modules; and (b) the gxsnmp package; does not properly validate length values during decoding of ASN.1 BER data, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a length greater than the working buffer, which can lead to an unspecified overflow; (2) an oid length of zero, which can lead to an off-by-one error; or (3) an indefinite length for a primitive encoding.
Source: NIST NVD / MITRE CVE Database
Vulnerability details: The asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6 before 2.6.25.5, as used in the cifs and ip_nat_snmp_basic modules; and (b) the gxsnmp package; does not properly validate length values during decoding of ASN.1 BER data, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a length greater than the working buffer, which can lead to an unspecified overflow; (2) an oid length of zero, which can lead to an off-by-one error; CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.
Exploitation Likelihood: LOW
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | rule-based-v1 |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 046032fa1afbede158f10015e0d3fa693a11ba657a0ad83f56eda5773a88cc43b78d9d7547fc4c04e82763a5f48f3845b6ddbb0de9f69afbcf306ee4de99f632 |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →