PT-2005-3066 · Netbsd · Netbsd
Published
2005-07-05
·
Updated
2008-09-10
·
CVE-2005-2134
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
NetBSD versions 1.6 through 2.0.2
Description:
The issue allows local users to cause a denial of service, resulting in a kernel crash. This is achieved by using the set-parameters ioctl on an audio device to change the block size and set the pause state to "unpaused" in the same ioctl, which causes a divide-by-zero error.
Recommendations:
For NetBSD versions 1.6 through 2.0.2, consider disabling the set-parameters ioctl on audio devices as a temporary workaround until a patch is available. Restrict access to the clcs and emuxki drivers to minimize the risk of exploitation. Avoid using the set-parameters ioctl to change the block size and pause state simultaneously on audio devices until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netbsd