CVE-2006-0098: Medium severity OpenBSD OpenBSD vulnerability
Published Jan 6, 2006
·Updated
The dupfdopen function in sys/kern/kerndescrip.c in OpenBSD 3.7 and 3.8 allows local users to re-open arbitrary files by using setuid programs to access file descriptors using /dev/fd/.
Affected Software
2 affected components
OpenBSD OpenBSD=3.7
OpenBSD OpenBSD=3.8
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jan 6, 2006
CVE Published
11:03 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0098?
CVE-2006-0098 has a moderate severity rating, as it allows local users to potentially gain unauthorized access to files.
2
How do I fix CVE-2006-0098?
To fix CVE-2006-0098, users should upgrade to a patched version of OpenBSD that resolves this vulnerability.
3
Which versions of OpenBSD are affected by CVE-2006-0098?
CVE-2006-0098 affects OpenBSD versions 3.7 and 3.8.
4
What causes CVE-2006-0098?
CVE-2006-0098 is caused by the dupfdopen function allowing local users to re-open arbitrary files through the misuse of file descriptors.
5
Can remote users exploit CVE-2006-0098?
No, CVE-2006-0098 can only be exploited by local users with access to a vulnerable system.