PT-1997-1207 · Bsd · 4.4 Bsd Kernel

Publicado

1997-09-15

·

Atualizado

2017-10-10

·

CVE-1999-1214

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions 4.4 BSD kernel
Description The issue concerns the asynchronous I/O facility in the 4.4 BSD kernel, which fails to check user credentials when setting the recipient of I/O notification. This allows local users to cause a denial of service by using certain ioctl and fcntl calls to send the signal to an arbitrary process ID.
Recommendations For 4.4 BSD kernel, consider restricting access to ioctl and fcntl calls to minimize the risk of exploitation. As a temporary workaround, limit the ability of local users to send signals to arbitrary process IDs until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-1999-1214

Produtos afetados

4.4 Bsd Kernel