NetBSD 'hack(6)' Multiple Privilege Escalation Vulnerabilities
BID:35542
Info
NetBSD 'hack(6)' Multiple Privilege Escalation Vulnerabilities
| Bugtraq ID: | 35542 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 30 2009 12:00AM |
| Updated: | May 19 2010 10:02AM |
| Credit: | David A. Holland |
| Vulnerable: |
NetBSD NetBSD 4.0.1 NetBSD NetBSD 5.0 NetBSD NetBSD 4.0 |
| Not Vulnerable: | |
Discussion
NetBSD 'hack(6)' Multiple Privilege Escalation Vulnerabilities
The NetBSD 'hack(6)' game is prone to multiple privilege-escalation vulnerabilities caused by buffer-overflow errors because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
A local attacker may exploit these issues to elevate privileges to the 'games' group.
The NetBSD 'hack(6)' game is prone to multiple privilege-escalation vulnerabilities caused by buffer-overflow errors because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
A local attacker may exploit these issues to elevate privileges to the 'games' group.
Exploit / POC
NetBSD 'hack(6)' Multiple Privilege Escalation Vulnerabilities
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proofs of concept are available:
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proofs of concept are available:
Solution / Fix
NetBSD 'hack(6)' Multiple Privilege Escalation Vulnerabilities
Solution:
The vendor has released patches. Please see the references for details.
Solution:
The vendor has released patches. Please see the references for details.
References
NetBSD 'hack(6)' Multiple Privilege Escalation Vulnerabilities
References:
References:
- NetBSD Homepage (NetBSD)
- NetBSD Security Advisory 2009-007 (NetBSD)