PT-2004-2908 · Netbsd+1 · Netbsd+1
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-2012
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NetBSD versions prior to April 16, 2004
FreeBSD (affected versions not specified)
Description
The issue allows local users to gain root privileges due to the systrace exit function in the systrace utility not verifying the owner of the /dec/systrace connection before setting euid to 0.
Recommendations
For NetBSD versions prior to April 16, 2004, update to a version released after April 16, 2004.
For FreeBSD, at the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freebsd
Netbsd