[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2001-0268Date: (C)2001-05-03   (M)2023-12-22


The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by creating a segment call gate in the Local Descriptor Table (LDT) with a target that specifies an arbitrary kernel address.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.2
Exploit Score: 3.9
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
http://archives.neohapsis.com/archives/bugtraq/2001-02/0353.html
http://www.openbsd.org/errata.html#userldt
BID-2739
OSVDB-6141
CSSA-2001-SCO.35
NetBSD-SA:2001-002
VU#358960
user-ldt-validation(6222)

CPE    2
cpe:/o:netbsd:netbsd:1.5
cpe:/o:openbsd:openbsd:2.8

© SecPod Technologies