PT-2001-1497 · Openbsd+1 · Openbsd+1

Publicado

2001-05-03

·

Atualizado

2017-10-10

·

CVE-2001-0268

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NetBSD versions 1.5 and earlier OpenBSD versions 2.8 and earlier
Description The issue concerns the i386 set ldt system call, which, when the USER LDT kernel option is enabled, fails to validate a call gate target. This allows local users to gain root privileges by creating a segment call gate in the Local Descriptor Table (LDT) with a target that specifies an arbitrary kernel address.
Recommendations For NetBSD versions 1.5 and earlier, consider disabling the USER LDT kernel option as a temporary workaround until a patch is available. For OpenBSD versions 2.8 and earlier, consider disabling the USER LDT kernel option as a temporary workaround until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-0268

Produtos afetados

Netbsd
Openbsd