Vulnerability Name:

CVE-2005-4783 (CCN-26291)

Assigned:2005-11-01
Published:2005-11-01
Updated:2008-09-05
Summary:kernfs_xread in kernfs_vnops.c in NetBSD before 20050831 does not check for a negative offset when reading the message buffer, which allows local users to read arbitrary kernel memory.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2005-4783

Source: CONFIRM
Type: Patch
http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/miscfs/kernfs/kernfs_vnops.c

Source: CONFIRM
Type: Patch
http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/miscfs/kernfs/kernfs_vnops.c.diff?r1=1.110&r2=1.111&f=h

Source: MLIST
Type: UNKNOWN
[netbsd-announce] 20051031 Announcing update 2.0.3 - source only

Source: CONFIRM
Type: Patch
http://releng.netbsd.org/cgi-bin/req-3.cgi?show=727

Source: CCN
Type: SECTRACK ID: 1015132
NetBSD Bugs in Kernel, Networking, and Application Code May Let Local Users Deny Service or Gain Elevated Privileges

Source: SECTRACK
Type: Patch
1015132

Source: OSVDB
Type: Patch
20729

Source: CCN
Type: OSVDB ID: 20729
NetBSD Message Buffer Negative Offset Arbitrary Kernel Memory Access

Source: NETBSD
Type: Patch
NetBSD-SA2006-001

Source: CCN
Type: BID-15264
NetBSD KernFS Local Kernel Memory Disclosure Vulnerability

Source: XF
Type: UNKNOWN
netbsd-kernfsvnopsc-obtain-information(26291)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:netbsd:netbsd:1.6:*:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:2.0:*:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:2.0.3:*:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:2.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:netbsd:netbsd:2.0:*:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:2.0.1:*:*:*:*:*:*:*
  • OR cpe:/o:netbsd:netbsd:2.0.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    netbsd netbsd 1.6
    netbsd netbsd 2.0
    netbsd netbsd 2.0.3
    netbsd netbsd 2.1
    netbsd netbsd 2.0
    netbsd netbsd 2.0.1
    netbsd netbsd 2.0.2