PT-2001-2144 · Netbsd · Netbsd
Published
2001-07-24
·
Updated
2017-10-10
·
CVE-2001-0993
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
NetBSD versions 1.3 through 1.5
Description
The issue concerns a problem with the
sendmsg function that allows local users to cause a denial of service, potentially leading to a kernel trap or panic. This is achieved by using a msghdr structure with a large msg controllen length.Recommendations
For NetBSD versions 1.3 through 1.5, consider restricting the use of the
sendmsg function until a patch is available. As a temporary workaround, avoid using the msghdr structure with large msg controllen lengths to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netbsd