CVE-2005-4779 - CERT CVE
ID CVE-2005-4779
Sažetak verifiedexecioctl in verified_exec.c in NetBSD 2.0.2 calls NDINIT with UIO_USERSPACE rather than UID_SYSSPACE, which removes the functionality of the verified exec kernel subsystem and might allow local users to execute Trojan horse programs.
Reference
CVSS
Base: 3.6
Impact: 4.9
Exploitability:3.9
Pristup
VektorSloženostAutentikacija
LOCAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL PARTIAL NONE
CVSS vektor AV:L/AC:L/Au:N/C:P/I:P/A:N
Zadnje važnije ažuriranje 05-09-2008 - 20:57
Objavljeno 31-12-2005 - 05:00