CVE-2006-1588: Low severity netbsd netbsd vulnerability
Published Apr 3, 2006
·Updated
The bridge ioctl (ifbridge code) in NetBSD 1.6 through 3.0 does not clear sensitive memory before copying ioctl results to the requesting process, which allows local users to obtain portions of kernel memory.
Affected Software
10 affected components
NetBSD NetBSD=1.6
NetBSD NetBSD=1.6-beta
NetBSD NetBSD=1.6.1
NetBSD NetBSD=1.6.2
NetBSD NetBSD=2.0
NetBSD NetBSD=2.0.1
NetBSD NetBSD=2.0.2
NetBSD NetBSD=2.0.3
NetBSD NetBSD=2.1
NetBSD NetBSD=3.0
Remediation
Patch Available
Patch Available
Event History
Apr 3, 2006
CVE Published
10:04 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1588?
CVE-2006-1588 is considered a medium severity vulnerability due to the potential exposure of sensitive kernel memory to local users.
2
How do I fix CVE-2006-1588?
To fix CVE-2006-1588, you should upgrade to a version of NetBSD that contains the patch for this vulnerability.
3
Who is affected by CVE-2006-1588?
CVE-2006-1588 affects users of NetBSD versions 1.6 through 3.0.
4
What type of attack does CVE-2006-1588 enable?
CVE-2006-1588 enables local users to read sensitive information from kernel memory via the bridge ioctl.
5
Is CVE-2006-1588 an exploit that can be executed remotely?
CVE-2006-1588 is not a remote exploit; it requires local access to the affected system for execution.