CVE Vulnerabilities

CVE-2006-1588

Published: Apr 03, 2006 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The bridge ioctl (if_bridge code) in NetBSD 1.6 through 3.0 does not clear sensitive memory before copying ioctl results to the requesting process, which allows local users to obtain portions of kernel memory.

Affected Software

Name Vendor Start Version End Version
Netbsd Netbsd 1.6 (including) 1.6 (including)
Netbsd Netbsd 1.6-beta (including) 1.6-beta (including)
Netbsd Netbsd 1.6.1 (including) 1.6.1 (including)
Netbsd Netbsd 1.6.2 (including) 1.6.2 (including)
Netbsd Netbsd 2.0 (including) 2.0 (including)
Netbsd Netbsd 2.0.1 (including) 2.0.1 (including)
Netbsd Netbsd 2.0.2 (including) 2.0.2 (including)
Netbsd Netbsd 2.0.3 (including) 2.0.3 (including)
Netbsd Netbsd 2.1 (including) 2.1 (including)
Netbsd Netbsd 3.0 (including) 3.0 (including)

References