PT-2003-1226 · Netbsd · Netbsd

Published

2003-04-02

·

Updated

2008-09-05

·

CVE-2002-1490

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions NetBSD versions 1.4 through 1.6 beta
Description The issue allows local users to cause a denial of service, resulting in a kernel panic. This is achieved through a series of calls to the TIOCSCTTY ioctl, which causes an integer overflow in a structure counter. The counter is set to zero, leading to the freeing of memory that is still in use by other processes.
Recommendations For NetBSD versions 1.4 through 1.6 beta, as a temporary workaround, consider restricting access to the TIOCSCTTY ioctl until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1490

Affected Products

Netbsd