The bridge ioctl (if_bridge code) in NetBSD 1.6 through 3.0 does not clear sensitive memory before copying ioctl results to the requesting process, which allows local users to obtain portions of kernel memory.
References
Link | Resource |
---|---|
ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-005.txt.asc | Vendor Advisory |
http://secunia.com/advisories/19464 | Vendor Advisory |
http://securitytracker.com/id?1015846 | Patch |
http://www.osvdb.org/24262 | |
http://www.securityfocus.com/bid/17312 | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/25582 |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2006-04-03 10:04
Updated : 2024-02-28 10:42
NVD link : CVE-2006-1588
Mitre link : CVE-2006-1588
CVE.ORG link : CVE-2006-1588
JSON object : View
Products Affected
netbsd
- netbsd
CWE