| Vulnerability Name: | CVE-2002-1500 (CCN-10114) | ||||||||
| Assigned: | 2002-09-17 | ||||||||
| Published: | 2002-09-17 | ||||||||
| Updated: | 2008-09-05 | ||||||||
| Summary: | Buffer overflow in (1) mrinfo, (2) mtrace, and (3) pppd in NetBSD 1.4.x through 1.6 allows local users to gain privileges by executing the programs after filling the file descriptor tables, which produces file descriptors larger than FD_SETSIZE, which are not checked by FD_SET(). | ||||||||
| CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||
| References: | Source: NETBSD Type: UNKNOWN NetBSD-SA2002-014 Source: CCN Type: Full-Disclosure Mailing List, Mon Sep 16 2002 - 21:39:49 CDT fd_set overrun in mbone tools and pppd Source: MITRE Type: CNA CVE-2002-1500 Source: XF Type: Patch, Vendor Advisory netbsd-fdset-bo(10114) Source: CCN Type: OSVDB ID: 7567 NetBSD mtrace FD_SET File Descriptor Overflow Source: CCN Type: OSVDB ID: 7568 NetBSD pppd FD_SET File Descriptor Overflow Source: CCN Type: OSVDB ID: 7569 NetBSD mrinfo FD_SET File Descriptor Overflow Source: BID Type: Patch, Vendor Advisory 5727 Source: CCN Type: BID-5727 NetBSD IPv4 Multicast Tools Buffer Overflow Vulnerability Source: XF Type: UNKNOWN netbsd-fdset-bo(10114) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||