CVE Vulnerabilities

CVE-2009-2793

Published: Sep 18, 2009 | Modified: Oct 10, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The kernel in NetBSD, probably 5.0.1 and earlier, on x86 platforms does not properly handle a pre-commit failure of the iret instruction, which might allow local users to gain privileges via vectors related to a tempEIP pseudocode variable that is outside of the code-segment limits.

Affected Software

Name Vendor Start Version End Version
Netbsd Netbsd 1.5.3 1.5.3
Netbsd Netbsd 1.6 1.6
Netbsd Netbsd 1.3 1.3
Netbsd Netbsd 5.0 5.0
Netbsd Netbsd 1.5 1.5
Netbsd Netbsd 4.0 4.0
Netbsd Netbsd 2.1 2.1
Netbsd Netbsd 1.2.1 1.2.1
Netbsd Netbsd 1.3.1 1.3.1
Netbsd Netbsd 2.0.2 2.0.2
Netbsd Netbsd 1.6.1 1.6.1
Netbsd Netbsd 3.0.1 3.0.1
Netbsd Netbsd 2.0.3 2.0.3
Netbsd Netbsd 3.0.2 3.0.2
Netbsd Netbsd 1.6.2 1.6.2
Netbsd Netbsd 1.3.3 1.3.3
Netbsd Netbsd 4.0.1 4.0.1
Netbsd Netbsd 1.0 1.0
Netbsd Netbsd 0.9 0.9
Netbsd Netbsd 1.5.1 1.5.1
Netbsd Netbsd 0.8 0.8
Netbsd Netbsd 1.1 1.1
Netbsd Netbsd 1.5.2 1.5.2
Netbsd Netbsd 2.0.1 2.0.1
Netbsd Netbsd * 5.0.1
Netbsd Netbsd 3.1 3.1
Netbsd Netbsd 3.0 3.0
Netbsd Netbsd 1.3.2 1.3.2
Netbsd Netbsd 2.0 2.0
Netbsd Netbsd 1.2 1.2

References