NetBSD Kernel Unspecified Local Buffer Overflow Vulnerability
BID:22945
Info
NetBSD Kernel Unspecified Local Buffer Overflow Vulnerability
| Bugtraq ID: | 22945 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-1523 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 13 2007 12:00AM |
| Updated: | May 12 2015 07:33PM |
| Credit: | Christer �?berg is credited with the discovery of this vulnerability. |
| Vulnerable: |
NetBSD NetBSD 3.0.2 NetBSD NetBSD 3.0.1 NetBSD NetBSD 2.1 NetBSD NetBSD 2.0.3 NetBSD NetBSD 2.0.2 NetBSD NetBSD 2.0.1 NetBSD NetBSD 2.0 NetBSD NetBSD 1.6.2 NetBSD NetBSD 1.6.1 NetBSD NetBSD 1.6 beta NetBSD NetBSD 1.6 NetBSD NetBSD 1.5.3 NetBSD NetBSD 1.5.2 NetBSD NetBSD 1.5.1 NetBSD NetBSD 1.5 x86 NetBSD NetBSD 1.5 sh3 NetBSD NetBSD 1.5 NetBSD NetBSD 1.4.3 NetBSD NetBSD 1.4.2 x86 NetBSD NetBSD 1.4.2 SPARC NetBSD NetBSD 1.4.2 arm32 NetBSD NetBSD 1.4.2 Alpha NetBSD NetBSD 1.4.2 NetBSD NetBSD 1.4.1 x86 NetBSD NetBSD 1.4.1 SPARC NetBSD NetBSD 1.4.1 sh3 NetBSD NetBSD 1.4.1 arm32 NetBSD NetBSD 1.4.1 Alpha NetBSD NetBSD 1.4.1 NetBSD NetBSD 1.4 x86 NetBSD NetBSD 1.4 SPARC NetBSD NetBSD 1.4 arm32 NetBSD NetBSD 1.4 Alpha NetBSD NetBSD 1.4 NetBSD NetBSD 1.3.3 NetBSD NetBSD 1.3.2 NetBSD NetBSD 1.3.1 NetBSD NetBSD 1.3 NetBSD NetBSD 1.2.1 NetBSD NetBSD 1.2 NetBSD NetBSD 1.1 NetBSD NetBSD 1.0 NetBSD NetBSD Current NetBSD NetBSD 4.0 BETA2 NetBSD NetBSD 4.0 NetBSD NetBSD 4,0_Beta NetBSD NetBSD 3.1_RC3 NetBSD NetBSD 3.1 NetBSD NetBSD 3,1_RC1 NetBSD NetBSD 2.1.1 NetBSD NetBSD 2.0.4 Navision Financials Server 3.0 |
| Not Vulnerable: | |
Discussion
NetBSD Kernel Unspecified Local Buffer Overflow Vulnerability
NetBSD is prone to an unspecified kernel heap-based buffer-overflow vulnerability.
Attackers may exploit this issue to execute arbitrary machine code in the context of the affected kernel. Failed attempts may result in denial-of-service conditions. Successful exploits will likely result in a complete compromise of the affected computer.
Reportedly, this issue also affects older versions of OpenBSD and FreeBSD.
NetBSD is prone to an unspecified kernel heap-based buffer-overflow vulnerability.
Attackers may exploit this issue to execute arbitrary machine code in the context of the affected kernel. Failed attempts may result in denial-of-service conditions. Successful exploits will likely result in a complete compromise of the affected computer.
Reportedly, this issue also affects older versions of OpenBSD and FreeBSD.
Exploit / POC
NetBSD Kernel Unspecified Local Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
NetBSD Kernel Unspecified Local Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
NetBSD Kernel Unspecified Local Buffer Overflow Vulnerability
References:
References:
- Kernel Wars (Joel Eriksson, Karl Janmar, Christer �?berg)
- NetBSD Homepage (NetBSD)