2.1

CVE-2006-1588

The bridge ioctl (if_bridge code) in NetBSD 1.6 through 3.0 does not clear sensitive memory before copying ioctl results to the requesting process, which allows local users to obtain portions of kernel memory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netbsd ≫ Netbsd Version 1.6
Netbsd ≫ Netbsd Version 1.6 Update beta
Netbsd ≫ Netbsd Version 1.6.1
Netbsd ≫ Netbsd Version 1.6.2
Netbsd ≫ Netbsd Version 2.0
Netbsd ≫ Netbsd Version 2.0.1
Netbsd ≫ Netbsd Version 2.0.2
Netbsd ≫ Netbsd Version 2.0.3
Netbsd ≫ Netbsd Version 2.1
Netbsd ≫ Netbsd Version 3.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.259
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-005.txt.asc
Vendor Advisory
http://secunia.com/advisories/19464
Vendor Advisory
http://securitytracker.com/id?1015846
Patch
http://www.osvdb.org/24262
http://www.securityfocus.com/bid/17312
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/25582