CVE-2004-2012: High severity niels provos systrace vulnerability
The systraceexit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not verify the owner of the /dec/systrace connection before setting euid to 0, which allows local users to gain root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2012?
CVE-2004-2012 is considered a high severity vulnerability due to its potential for local privilege escalation.
How does CVE-2004-2012 affect system security?
CVE-2004-2012 allows unauthorized local users to gain root privileges, compromising the integrity of the system.
How do I fix CVE-2004-2012?
To fix CVE-2004-2012, update the systrace utility to a version that has addressed the ownership verification flaw.
Which software versions are affected by CVE-2004-2012?
CVE-2004-2012 affects multiple versions of the systrace utility, including versions 1.1 to 1.5 and certain FreeBSD ports.
What platforms are impacted by CVE-2004-2012?
CVE-2004-2012 impacts NetBSD versions 2.0 and earlier, as well as FreeBSD ports using impacted systrace versions.