CVE-2005-4779: Low severity NetBSD NetBSD vulnerability
Published Dec 31, 2005
·Updated
verifiedexecioctl in verifiedexec.c in NetBSD 2.0.2 calls NDINIT with UIOUSERSPACE rather than UIDSYSSPACE, which removes the functionality of the verified exec kernel subsystem and might allow local users to execute Trojan horse programs.
Affected Software
3 affected components
NetBSD NetBSD=2.0
NetBSD NetBSD=2.0.1
NetBSD NetBSD=2.0.2
Remediation
Patch Available
Event History
Dec 31, 2005
CVE Published
05:00 AM
Apr 13, 2006
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-4779?
CVE-2005-4779 is considered a medium severity vulnerability due to its potential to allow local users to execute unauthorized programs.
2
How do I fix CVE-2005-4779?
To address CVE-2005-4779, it's recommended to upgrade to a patched version of NetBSD that resolves this issue.
3
What versions of NetBSD are affected by CVE-2005-4779?
CVE-2005-4779 affects NetBSD versions 2.0, 2.0.1, and 2.0.2.
4
What functionality is compromised by CVE-2005-4779?
CVE-2005-4779 compromises the verified exec kernel subsystem, potentially allowing the execution of Trojan horse programs.
5
Who can exploit CVE-2005-4779?
CVE-2005-4779 can be exploited by local users on the affected NetBSD systems.