PT-2001-1497 · Openbsd+1 · Openbsd+1
Publicado
2001-05-03
·
Atualizado
2017-10-10
·
CVE-2001-0268
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NetBSD versions 1.5 and earlier
OpenBSD versions 2.8 and earlier
Description
The issue concerns the i386 set ldt system call, which, when the USER LDT kernel option is enabled, fails to validate a call gate target. This allows local users to gain root privileges by creating a segment call gate in the Local Descriptor Table (LDT) with a target that specifies an arbitrary kernel address.
Recommendations
For NetBSD versions 1.5 and earlier, consider disabling the USER LDT kernel option as a temporary workaround until a patch is available.
For OpenBSD versions 2.8 and earlier, consider disabling the USER LDT kernel option as a temporary workaround until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Netbsd
Openbsd