7.2

CVE-2004-2012

Exploit
The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not verify the owner of the /dec/systrace connection before setting euid to 0, which allows local users to gain root privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Niels ≫ Provos Systrace Version 1.1
Niels ≫ Provos Systrace Version 1.2
Niels ≫ Provos Systrace Version 1.3
Niels ≫ Provos Systrace Version 1.4
Niels ≫ Provos Systrace Version 1.5
Vladimir Kotal ≫ Systrace Port For Freebsd Version 2004-03-09
Vladimir Kotal ≫ Systrace Port For Freebsd Version 2004-06-02
Netbsd ≫ Netbsd Version 2.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.85% 0.535
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2004-007.txt.asc
http://marc.info/?l=bugtraq&m=108432258920570&w=2
http://secunia.com/advisories/11585
http://www.securityfocus.com/bid/10320
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/16110