CVE Vulnerabilities

CVE-2004-2012

Published: Dec 31, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not verify the owner of the /dec/systrace connection before setting euid to 0, which allows local users to gain root privileges.

Affected Software

NameVendorStart VersionEnd Version
Provos_systraceNiels1.1 (including)1.1 (including)
Provos_systraceNiels1.2 (including)1.2 (including)
Provos_systraceNiels1.3 (including)1.3 (including)
Provos_systraceNiels1.4 (including)1.4 (including)
Provos_systraceNiels1.5 (including)1.5 (including)
Systrace_port_for_freebsdVladimir_kotal2004-03-09 (including)2004-03-09 (including)
Systrace_port_for_freebsdVladimir_kotal2004-06-02 (including)2004-06-02 (including)

References