PT-2017-1722 · Openbsd · Openbsd

Jesse Hertz

·

Publicado

2017-03-07

·

Atualizado

2017-03-09

·

CVE-2016-6246

CVSS v2.0

4.9

Média

VetorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenBSD versions 5.8 through 5.9
Description The issue allows certain local users with kern.usermount privileges to cause a denial of service, resulting in a kernel panic. This can be achieved by mounting a tmpfs with a VNOVAL in the username, groupname, or device name of the root node. The problem exists due to insufficient input validation.
Recommendations For OpenBSD versions 5.8 and 5.9, consider restricting the kern.usermount privileges to prevent local users from mounting tmpfs with malicious settings until a patch is available. As a temporary workaround, avoid using VNOVAL in the username, groupname, or device name of the root node when mounting a tmpfs.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-00875
CVE-2016-6246

Produtos afetados

Openbsd