PT-2005-3066 · Netbsd · Netbsd

Published

2005-07-05

·

Updated

2008-09-10

·

CVE-2005-2134

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: NetBSD versions 1.6 through 2.0.2
Description: The issue allows local users to cause a denial of service, resulting in a kernel crash. This is achieved by using the set-parameters ioctl on an audio device to change the block size and set the pause state to "unpaused" in the same ioctl, which causes a divide-by-zero error.
Recommendations: For NetBSD versions 1.6 through 2.0.2, consider disabling the set-parameters ioctl on audio devices as a temporary workaround until a patch is available. Restrict access to the clcs and emuxki drivers to minimize the risk of exploitation. Avoid using the set-parameters ioctl to change the block size and pause state simultaneously on audio devices until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2134

Affected Products

Netbsd