Multiple Vendor Call Gate Creation Input Validation Vulnerability
BID:2739
Info
Multiple Vendor Call Gate Creation Input Validation Vulnerability
| Bugtraq ID: | 2739 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Yes |
| Published: | Feb 16 2001 12:00AM |
| Updated: | Feb 16 2001 12:00AM |
| Credit: | This vulnerability was first published by NetBSD on February 16, 2001. |
| Vulnerable: |
Sun Trusted Solaris 8.0 x86 Sun Trusted Solaris 7.0 x86 Sun Solaris 8_x86 Sun Solaris 7.0_x86 Sun Solaris 2.6_x86 OpenBSD OpenBSD 2.8 OpenBSD OpenBSD 2.7 OpenBSD OpenBSD 2.6 OpenBSD OpenBSD 2.5 OpenBSD OpenBSD 2.4 NetBSD NetBSD 1.4.2 x86 NetBSD NetBSD 1.4.1 x86 NetBSD NetBSD 1.4 x86 |
| Not Vulnerable: | |
Discussion
Multiple Vendor Call Gate Creation Input Validation Vulnerability
In some i386 operating systems, the mechanisms for setting LDT entries contain an input validation error that can be exploited when creating call gates. By default on NetBSD and Solaris systems, it may be possible for users to create malicious LDT entries resulting in kernel code at arbitrary addresses being executed when the procedure is called. It has been reported that OpenBSD contains this vulnerability, however it is not present in default kernels.
It is likely that this vulnerability can be used to gain root privileges.
In some i386 operating systems, the mechanisms for setting LDT entries contain an input validation error that can be exploited when creating call gates. By default on NetBSD and Solaris systems, it may be possible for users to create malicious LDT entries resulting in kernel code at arbitrary addresses being executed when the procedure is called. It has been reported that OpenBSD contains this vulnerability, however it is not present in default kernels.
It is likely that this vulnerability can be used to gain root privileges.
Exploit / POC
Multiple Vendor Call Gate Creation Input Validation Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Multiple Vendor Call Gate Creation Input Validation Vulnerability
References:
References:
- NetBSD Security Page (NetBSD)
- OpenBSD Security Information (OpenBSD)
- Security Patch Downloads (Sun Microsystems)
- Sunsolve Online(tm) (Sun Microsystems)