OpenBSD 2.9 through 3.1 allows local users to cause a denial of service (resource exhaustion) and gain root privileges by filling the kernel's file descriptor table and closing file descriptors 0, 1, or 2 before executing a privileged process, which is not properly handled when OpenBSD fails to open an alternate descriptor.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:39
Type | Values Removed | Values Added |
---|---|---|
References | () http://online.securityfocus.com/archive/1/271702 - | |
References | () http://www.iss.net/security_center/static/9048.php - Patch, Vendor Advisory | |
References | () http://www.kb.cert.org/vuls/id/314963 - US Government Resource | |
References | () http://www.openbsd.org/errata.html#fdalloc2 - | |
References | () http://www.osvdb.org/5114 - | |
References | () http://www.osvdb.org/5715 - | |
References | () http://www.securityfocus.com/bid/4708 - |
Information
Published : 2002-08-12 04:00
Updated : 2024-11-20 23:39
NVD link : CVE-2002-0766
Mitre link : CVE-2002-0766
CVE.ORG link : CVE-2002-0766
JSON object : View
Products Affected
openbsd
- openbsd
CWE