CVE Vulnerabilities

CVE-2002-1490

Published: Apr 02, 2003 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

NetBSD 1.4 through 1.6 beta allows local users to cause a denial of service (kernel panic) via a series of calls to the TIOCSCTTY ioctl, which causes an integer overflow in a structure counter and sets the counter to zero, which frees memory that is still in use by other processes.

Affected Software

Name Vendor Start Version End Version
Netbsd Netbsd 1.4 (including) 1.4 (including)
Netbsd Netbsd 1.4.1 (including) 1.4.1 (including)
Netbsd Netbsd 1.4.2 (including) 1.4.2 (including)
Netbsd Netbsd 1.4.3 (including) 1.4.3 (including)
Netbsd Netbsd 1.5 (including) 1.5 (including)
Netbsd Netbsd 1.5.1 (including) 1.5.1 (including)
Netbsd Netbsd 1.5.2 (including) 1.5.2 (including)
Netbsd Netbsd 1.5.3 (including) 1.5.3 (including)
Netbsd Netbsd 1.6-beta (including) 1.6-beta (including)

References