PT-2005-5442 · Netbsd · Netbsd
Published
2005-12-31
·
Updated
2008-09-05
·
CVE-2005-4779
CVSS v2.0
3.6
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
NetBSD version 2.0.2
Description
The issue is related to the verifiedexecioctl in verified exec.c, which calls NDINIT with UIO USERSPACE instead of UID SYSSPACE. This removes the functionality of the verified exec kernel subsystem and might allow local users to execute malicious programs.
Recommendations
For NetBSD version 2.0.2, consider applying a patch or fix that corrects the NDINIT call to use UID SYSSPACE instead of UIO USERSPACE to restore the functionality of the verified exec kernel subsystem.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netbsd