CVE-2004-1323: Low severity NetBSD NetBSD vulnerability
Published Dec 16, 2004
·Updated
Multiple syscalls in the compat subsystem for NetBSD before 2.0 allow local users to cause a denial of service (kernel crash) via a large signal number to (1) xxxsyskill, (2) xxxsyssigaction, and possibly other translation functions.
Affected Software
7 affected components
NetBSD NetBSD=1.5.3
NetBSD NetBSD=1.6
NetBSD NetBSD=1.5
NetBSD NetBSD=1.6.1
NetBSD NetBSD=1.6.2
NetBSD NetBSD=1.5.1
NetBSD NetBSD=1.5.2
Remediation
Patch Available
Patch Available
Event History
Dec 16, 2004
CVE Published
05:00 AM
Jan 6, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1323?
CVE-2004-1323 has a severity rating that indicates a denial of service risk due to a kernel crash.
2
How do I fix CVE-2004-1323?
To fix CVE-2004-1323, upgrade to a patched version of NetBSD that addresses these vulnerabilities.
3
What versions of NetBSD are affected by CVE-2004-1323?
CVE-2004-1323 affects multiple versions of NetBSD, including 1.5, 1.5.1, 1.5.2, 1.6, 1.6.1, and 1.6.2.
4
What are the potential impacts of CVE-2004-1323?
The potential impacts of CVE-2004-1323 include a denial of service scenario leading to kernel crashes.
5
Who can exploit CVE-2004-1323?
Local users can exploit CVE-2004-1323 by sending a large signal number to specific system calls.