PT-2005-5442 · Netbsd · Netbsd
Publicado
2005-12-31
·
Atualizado
2008-09-05
·
CVE-2005-4779
CVSS v2.0
3.6
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
NetBSD version 2.0.2
Description
The issue is related to the verifiedexecioctl in verified exec.c, which calls NDINIT with UIO USERSPACE instead of UID SYSSPACE. This removes the functionality of the verified exec kernel subsystem and might allow local users to execute malicious programs.
Recommendations
For NetBSD version 2.0.2, consider applying a patch or fix that corrects the NDINIT call to use UID SYSSPACE instead of UIO USERSPACE to restore the functionality of the verified exec kernel subsystem.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Netbsd