3.6
CVSSv2

CVE-2005-4779

Published: 31/12/2005 Updated: 05/09/2008
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

verifiedexecioctl in verified_exec.c in NetBSD 2.0.2 calls NDINIT with UIO_USERSPACE rather than UID_SYSSPACE, which removes the functionality of the verified exec kernel subsystem and might allow local users to execute Trojan horse programs.

Vulnerable Product Search on Vulmon Subscribe to Product

netbsd netbsd 2.0

netbsd netbsd 2.0.1

netbsd netbsd 2.0.2