CVE Vulnerabilities

CVE-2006-0145

Published: Jan 09, 2006 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The kernfs_xread function in kernfs in NetBSD 1.6 through 2.1, and OpenBSD 3.8, does not properly validate file offsets against negative 32-bit values that occur as a result of truncation, which allows local users to read arbitrary kernel memory and gain privileges via the lseek system call.

Affected Software

Name Vendor Start Version End Version
Netbsd Netbsd 1.6 (including) 1.6 (including)
Netbsd Netbsd 1.6-beta (including) 1.6-beta (including)
Netbsd Netbsd 1.6.1 (including) 1.6.1 (including)
Netbsd Netbsd 1.6.2 (including) 1.6.2 (including)
Netbsd Netbsd 2.0 (including) 2.0 (including)
Netbsd Netbsd 2.0.1 (including) 2.0.1 (including)
Netbsd Netbsd 2.0.2 (including) 2.0.2 (including)
Netbsd Netbsd 2.0.3 (including) 2.0.3 (including)
Netbsd Netbsd 2.1 (including) 2.1 (including)

References