CVE-2006-1814: Low severity netbsd netbsd vulnerability
Published Apr 18, 2006
·Updated
NetBSD 1.6, 2.0, 2.1 and 3.0 allows local users to cause a denial of service (memory exhaustion) by using the sysctl system call to lock a large buffer into physical memory.
Affected Software
10 affected components
NetBSD NetBSD=1.6
NetBSD NetBSD=2.1
NetBSD NetBSD=2.0.2
NetBSD NetBSD=1.6.1
NetBSD NetBSD=2.0.3
NetBSD NetBSD=1.6.2
NetBSD NetBSD=1.6-beta
NetBSD NetBSD=2.0.1
NetBSD NetBSD=3.0
NetBSD NetBSD=2.0
Event History
Apr 18, 2006
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1814?
CVE-2006-1814 is classified as a denial of service vulnerability due to memory exhaustion.
2
Which versions of NetBSD are affected by CVE-2006-1814?
CVE-2006-1814 affects NetBSD versions 1.6, 1.6.1, 1.6.2, 2.0, 2.0.1, 2.0.2, 2.0.3, and 3.0.
3
How do I fix CVE-2006-1814?
To mitigate CVE-2006-1814, users should upgrade to the latest available version of NetBSD that addresses this vulnerability.
4
What causes the vulnerability CVE-2006-1814?
CVE-2006-1814 is caused by local users using the sysctl system call to lock large buffers into physical memory, leading to memory exhaustion.
5
Can CVE-2006-1814 be exploited remotely?
No, CVE-2006-1814 can only be exploited locally by users with access to the system.