CVE-2003-1289

The iBCS2 system call translator for statfs in NetBSD 1.5 through 1.5.3 and FreeBSD 4 up to 4.8-RELEASE-p2 and 5 up to 5.1-RELEASE-p1 allows local users to read portions of kernel memory (memory disclosure) via a large length parameter, which copies additional kernel memory into userland memory.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:freebsd:freebsd:*:release_p2:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:*:release_p1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:4.0:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:5.0:*:*:*:*:*:*:*
cpe:2.3:o:netbsd:netbsd:1.5:*:*:*:*:*:*:*
cpe:2.3:o:netbsd:netbsd:1.5.1:*:*:*:*:*:*:*
cpe:2.3:o:netbsd:netbsd:1.5.2:*:*:*:*:*:*:*
cpe:2.3:o:netbsd:netbsd:1.5.3:*:*:*:*:*:*:*

History

20 Nov 2024, 23:46

Type Values Removed Values Added
References () ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:10.ibcs2.asc - () ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:10.ibcs2.asc -
References () http://secunia.com/advisories/9504 - Patch, Vendor Advisory () http://secunia.com/advisories/9504 - Patch, Vendor Advisory
References () http://securitytracker.com/id?1007460 - Patch, Vendor Advisory () http://securitytracker.com/id?1007460 - Patch, Vendor Advisory
References () http://www.osvdb.org/2406 - Patch () http://www.osvdb.org/2406 - Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/12892 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/12892 -

Information

Published : 2003-12-31 05:00

Updated : 2024-11-20 23:46


NVD link : CVE-2003-1289

Mitre link : CVE-2003-1289

CVE.ORG link : CVE-2003-1289


JSON object : View

Products Affected

netbsd

  • netbsd

freebsd

  • freebsd