CVE Vulnerabilities

CVE-2005-4779

Published: Dec 31, 2005 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

verifiedexecioctl in verified_exec.c in NetBSD 2.0.2 calls NDINIT with UIO_USERSPACE rather than UID_SYSSPACE, which removes the functionality of the verified exec kernel subsystem and might allow local users to execute Trojan horse programs.

Affected Software

Name Vendor Start Version End Version
Netbsd Netbsd 2.0 (including) 2.0 (including)
Netbsd Netbsd 2.0.1 (including) 2.0.1 (including)
Netbsd Netbsd 2.0.2 (including) 2.0.2 (including)

References