CVE-2005-4741: High severity netbsd netbsd vulnerability
Published Dec 31, 2005
·Updated
NetBSD 1.6, NetBSD 2.0 through 2.1, and NetBSD-current before 20051031 allows local users to gain privileges by attaching a debugger to a setuid/setgid (PSUGID) process that performs an exec without a reset of real credentials.
Affected Software
8 affected components
NetBSD NetBSD=1.6
NetBSD NetBSD=1.6.1
NetBSD NetBSD=1.6.2
NetBSD NetBSD=2.0
NetBSD NetBSD=2.0.1
NetBSD NetBSD=2.0.2
NetBSD NetBSD=2.0.3
NetBSD NetBSD=2.1
Remediation
Event History
Dec 31, 2005
CVE Published
05:00 AM
Mar 19, 2006
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-4741?
CVE-2005-4741 is considered a high-severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2005-4741?
To address CVE-2005-4741, update to a patched version of NetBSD that resolves the vulnerability.
3
Who is affected by CVE-2005-4741?
CVE-2005-4741 affects local users on NetBSD versions 1.6 through 2.1 and NetBSD-current before 20051031.
4
What does CVE-2005-4741 exploit?
CVE-2005-4741 exploits the ability to attach a debugger to a setuid/setgid process during an exec without resetting real credentials.
5
What types of processes are involved in CVE-2005-4741?
CVE-2005-4741 involves setuid and setgid processes in the NetBSD operating system.