CVE-2003-1289: Low severity NetBSD NetBSD vulnerability
The iBCS2 system call translator for statfs in NetBSD 1.5 through 1.5.3 and FreeBSD 4 up to 4.8-RELEASE-p2 and 5 up to 5.1-RELEASE-p1 allows local users to read portions of kernel memory (memory disclosure) via a large length parameter, which copies additional kernel memory into userland memory.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1289?
CVE-2003-1289 has a medium severity rating due to its potential for memory disclosure.
How do I fix CVE-2003-1289?
To fix CVE-2003-1289, upgrade to a patched version of NetBSD or FreeBSD that addresses this vulnerability.
Which versions are affected by CVE-2003-1289?
CVE-2003-1289 affects NetBSD versions 1.5 through 1.5.3 and FreeBSD versions 4 up to 4.8-RELEASE-p2 and 5 up to 5.1-RELEASE-p1.
What kind of vulnerability is CVE-2003-1289?
CVE-2003-1289 is a memory disclosure vulnerability that allows local users to read kernel memory.
Can I mitigate CVE-2003-1289 without upgrading?
Mitigation for CVE-2003-1289 is limited; upgrading to a secure version is the most effective solution.