CVE-2005-4783: Low severity netbsd current vulnerability
Published Dec 31, 2005
·Updated
kernfsxread in kernfsvnops.c in NetBSD before 20050831 does not check for a negative offset when reading the message buffer, which allows local users to read arbitrary kernel memory.
Affected Software
4 affected components
NetBSD NetBSD=1.6
NetBSD NetBSD=2.0
NetBSD NetBSD=2.0.3
NetBSD NetBSD=2.1
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2005
CVE Published
05:00 AM
Apr 14, 2006
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-4783?
CVE-2005-4783 is considered a local privilege escalation vulnerability that allows users to access arbitrary kernel memory.
2
How do I fix CVE-2005-4783?
To fix CVE-2005-4783, update NetBSD to a version released after 20050831 where the issue has been addressed.
3
Who is affected by CVE-2005-4783?
CVE-2005-4783 affects local users on NetBSD versions 1.6, 2.0, 2.0.3, and 2.1.
4
What types of attacks can CVE-2005-4783 facilitate?
CVE-2005-4783 can facilitate local attacks that enable unauthorized access to sensitive kernel memory.
5
Is CVE-2005-4783 still relevant today?
While CVE-2005-4783 is an older vulnerability, it remains relevant for systems running affected versions of NetBSD that have not been updated.