4.6
CVSSv2

CVE-2006-0145

Published: 09/01/2006 Updated: 19/10/2018
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The kernfs_xread function in kernfs in NetBSD 1.6 up to and including 2.1, and OpenBSD 3.8, does not properly validate file offsets against negative 32-bit values that occur as a result of truncation, which allows local users to read arbitrary kernel memory and gain privileges via the lseek system call.

Vulnerable Product Search on Vulmon Subscribe to Product

netbsd netbsd 2.0.2

netbsd netbsd 2.0.3

netbsd netbsd 1.6

netbsd netbsd 1.6.1

netbsd netbsd 2.1

netbsd netbsd 2.0

netbsd netbsd 2.0.1

netbsd netbsd 1.6.2