| Vulnerability Name: | CVE-2001-0268 (CCN-6222) | ||||||||
| Assigned: | 2001-02-16 | ||||||||
| Published: | 2001-02-16 | ||||||||
| Updated: | 2017-10-10 | ||||||||
| Summary: | The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by creating a segment call gate in the Local Descriptor Table (LDT) with a target that specifies an arbitrary kernel address. | ||||||||
| CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||
| References: | Source: CCN Type: OpenBSD FTP site USER_LDT source patch Source: BUGTRAQ Type: UNKNOWN 20010219 Re: your mail Source: CALDERA Type: UNKNOWN CSSA-2001-SCO.35 Source: NETBSD Type: Patch, Vendor Advisory NetBSD-SA:2001-002 Source: MITRE Type: CNA CVE-2001-0268 Source: CCN Type: NetBSD Security Advisory 2001-002 Vulnerability in x86 USER_LDT validation Source: CCN Type: US-CERT VU#358960 BSD i386_set_ldt syscall does not appropriately validate call gate targets Source: CERT-VN Type: US Government Resource VU#358960 Source: OPENBSD Type: UNKNOWN 20010302 The USER_LDT kernel option allows an attacker to gain access to privileged areas of kernel memory. Source: CCN Type: OpenBSD Security Fix: Mar 2, 2001 The USER_LDT kernel option allows an attacker to gain access to privileged areas of kernel memory. Source: OSVDB Type: UNKNOWN 6141 Source: CCN Type: OSVDB ID: 6141 Multiple BSD USER_LDT Kernel Option Memory Access Source: BID Type: UNKNOWN 2739 Source: CCN Type: BID-2739 Multiple Vendor Call Gate Creation Input Validation Vulnerability Source: XF Type: UNKNOWN user-ldt-validation(6222) Source: XF Type: UNKNOWN user-ldt-validation(6222) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||