First published: Tue Mar 18 2003(Updated: )
Buffer overflow in (1) mrinfo, (2) mtrace, and (3) pppd in NetBSD 1.4.x through 1.6 allows local users to gain privileges by executing the programs after filling the file descriptor tables, which produces file descriptors larger than FD_SETSIZE, which are not checked by FD_SET().
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetBSD NetBSD | =1.5.3 | |
NetBSD NetBSD | =1.4 | |
NetBSD NetBSD | =1.5 | |
NetBSD NetBSD | =1.4.2 | |
NetBSD NetBSD | =1.4.2 | |
NetBSD NetBSD | =1.4.2 | |
NetBSD NetBSD | =1.4.1 | |
NetBSD NetBSD | =1.4.2 | |
NetBSD NetBSD | =1.5 | |
NetBSD NetBSD | =1.4.2 | |
NetBSD NetBSD | =1.4.1 | |
NetBSD NetBSD | =1.5.1 | |
NetBSD NetBSD | =1.5 | |
NetBSD NetBSD | =1.5.2 | |
NetBSD NetBSD | =1.4.3 | |
NetBSD NetBSD | =1.4 | |
NetBSD NetBSD | =1.4 | |
NetBSD NetBSD | =1.4.1 | |
NetBSD NetBSD | =1.4.1 | |
NetBSD NetBSD | =1.4.1 | |
NetBSD NetBSD | =1.4 | |
NetBSD NetBSD | =1.4.1 | |
NetBSD NetBSD | =1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1500 has a high severity rating due to the potential for local users to gain elevated privileges.
To fix CVE-2002-1500, update to a version of NetBSD that has addressed this buffer overflow vulnerability.
CVE-2002-1500 affects NetBSD versions 1.4.x to 1.6, including specific versions like 1.4, 1.4.1, 1.4.2, 1.5, and 1.5.3.
The vulnerability in CVE-2002-1500 is a buffer overflow that occurs when certain programs do not correctly check file descriptor limits.
CVE-2002-1500 is a local vulnerability and can only be exploited by users with access to the affected system.