Vulnerability Name: | CVE-2004-1323 (CCN-18564) | ||||||||
Assigned: | 2004-12-16 | ||||||||
Published: | 2004-12-16 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | Multiple syscalls in the compat subsystem for NetBSD before 2.0 allow local users to cause a denial of service (kernel crash) via a large signal number to (1) xxx_sys_kill, (2) xxx_sys_sigaction, and possibly other translation functions. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: NetBSD Security Advisory 2004-010 Insufficient argument validation in compat code Source: NETBSD Type: UNKNOWN NetBSD-SA2004-010 Source: MITRE Type: CNA CVE-2004-1323 Source: CCN Type: GLEG Web site NetBSD kernel local Denial of Service vulnerabilities Source: MISC Type: Patch, Vendor Advisory http://gleg.net/advisory_netbsd2.shtml Source: CCN Type: SA13501 NetBSD "compat" Privilege Escalation Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 13501 Source: CCN Type: OSVDB ID: 20409 NetBSD compat Translation Function Local DoS Source: CCN Type: BID-11996 NetBSD Multiple Local Unspecified Binary Compatibility Layer Vulnerabilities Source: XF Type: UNKNOWN netbsd-compat-gain-privileges(18564) Source: XF Type: UNKNOWN netbsd-compat-gain-privileges(18564) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |