3.6

CVE-2005-4779

verifiedexecioctl in verified_exec.c in NetBSD 2.0.2 calls NDINIT with UIO_USERSPACE rather than UID_SYSSPACE, which removes the functionality of the verified exec kernel subsystem and might allow local users to execute Trojan horse programs.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netbsd ≫ Netbsd Version 2.0
Netbsd ≫ Netbsd Version 2.0.1
Netbsd ≫ Netbsd Version 2.0.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.25
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.6 3.9 4.9
AV:L/AC:L/Au:N/C:P/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://mail-index.netbsd.org/netbsd-announce/2005/10/31/0000.html
Patch
http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/dev/verified_exec.c.diff?r1=1.4&r2=1.4.2.1&f=h
http://releng.netbsd.org/cgi-bin/req-2-0.cgi?show=1988
http://www.osvdb.org/20725
Patch