The kernfs_xread function in kernfs in NetBSD 1.6 through 2.1,...
Vulnerability Description
The kernfs_xread function in kernfs in NetBSD 1.6 through 2.1, and OpenBSD 3.8, does not properly validate file offsets against negative 32-bit values that occur as a result of truncation, which allows local users to read arbitrary kernel memory and gain privileges via the lseek system call.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-0145
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/18712
- http://www.securitylab.net/research/2006/02/advisory_netbsd_openbsd_kernfs.html
- http://securityreason.com/securityalert/405
- http://www.securityfocus.com/bid/16173
- http://secunia.com/advisories/18388
- http://www.osvdb.org/22293
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-001.txt.asc
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24035
- http://www.securityfocus.com/archive/1/423827/100/0/threaded
More from netbsd
View All →Affected Vendor
netbsd
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.