First published: Wed Feb 16 2000(Updated: )
procfs in BSD systems allows local users to gain root privileges by modifying the /proc/pid/mem interface via a modified file descriptor for stderr.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetBSD NetBSD | =1.4.1 | |
=1.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0094 has a high severity rating due to the potential for local users to gain root privileges.
To fix CVE-2000-0094, restrict access to the /proc/pid/mem interface or upgrade to a patched version of the operating system.
CVE-2000-0094 affects users of NetBSD 1.4.1 and potentially other BSD systems that utilize procfs.
CVE-2000-0094 is caused by a flaw in procfs that allows local users to manipulate memory mappings via stderr.
CVE-2000-0094 is not exploitable remotely, as it requires local user access to the system.