verifiedexecioctl in verified_exec.c in NetBSD 2.0.2 calls NDINIT with UIO_USERSPACE rather than UID_SYSSPACE, which removes the functionality of the verified exec kernel subsystem and might allow local users to execute Trojan horse programs.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:05
Type | Values Removed | Values Added |
---|---|---|
References | () http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/dev/verified_exec.c.diff?r1=1.4&r2=1.4.2.1&f=h - | |
References | () http://mail-index.netbsd.org/netbsd-announce/2005/10/31/0000.html - Patch | |
References | () http://releng.netbsd.org/cgi-bin/req-2-0.cgi?show=1988 - | |
References | () http://www.osvdb.org/20725 - Patch |
Information
Published : 2005-12-31 05:00
Updated : 2025-04-03 01:03
NVD link : CVE-2005-4779
Mitre link : CVE-2005-4779
CVE.ORG link : CVE-2005-4779
JSON object : View
Products Affected
netbsd
- netbsd
CWE