CVE-2006-5218

Integer overflow in the systrace_preprepl function (STRIOCREPLACE) in systrace in OpenBSD 3.9 and NetBSD 3 allows local users to cause a denial of service (crash), gain privileges, or read arbitrary kernel memory via large numeric arguments to the systrace ioctl.

Score4.6
Access VectorLOCAL
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactPARTIAL
Availability ImpactPARTIAL
Published2006-10-10 12:06:00.000-04
Last Modified2017-07-19 09:33:36.000-04

Vulnerable Software List

VendorProductVersions
Openbsd Openbsd 3.8, 3.9
Netbsd Netbsd 3.0

References

SourceLink
OPENBSD[3.9] 20061007 014: SECURITY FIX: October 7, 2006
MISChttp://scary.beasts.org/security/CESA-2006-003.html
SECTRACK1017009
BID20392
XFopenbsd-systracepreprepl-integer-overflow(29392)