NetBSD Pre-Commit Failure Processing Flaw May Let Local Users Gain Elevated Privileges
|
SecurityTracker Alert ID: 1022912 |
SecurityTracker URL: http://securitytracker.com/id/1022912
|
CVE Reference:
CVE-2009-2793
(Links to External Site)
|
Date: Sep 18 2009
|
Impact:
Root access via local system, User access via local system
|
Vendor Confirmed: Yes
|
|
Description:
A vulnerability was reported in NetBSD. A local user may be able to obtain elevated privileges on the target system.
A local user can trigger an iret instruction failure to potentially cause the kernel stack to become desynchronized. This may allow the local user to gain elevated privileges.
The original advisory is available at:
http://www.cr0.org/misc/CVE-2009-2793.txt
Tavis Ormandy and Julien Tinnes of the Google Security Team reported this vulnerability.
|
Impact:
A local user may be able to obtain elevated privileges on the target system.
|
Solution:
No solution was available at the time of this entry.
|
Vendor URL: www.NetBSD.org/Security/ (Links to External Site)
|
Cause:
Access control error, State error
|
|
Message History:
None.
|
Source Message Contents
|
|
[Original Message Not Available for Viewing]
|
|