First published: Mon Oct 09 2006(Updated: )
Integer overflow in the systrace_preprepl function (STRIOCREPLACE) in systrace in OpenBSD 3.9 and NetBSD 3 allows local users to cause a denial of service (crash), gain privileges, or read arbitrary kernel memory via large numeric arguments to the systrace ioctl.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenBSD | =3.8 | |
OpenBSD | =3.9 | |
NetBSD NetBSD | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5218 has a severity level that can potentially lead to a denial of service and privilege escalation.
To fix CVE-2006-5218, update your system to the latest version of OpenBSD or NetBSD that addresses this vulnerability.
CVE-2006-5218 affects OpenBSD 3.8 and 3.9, as well as NetBSD 3.0.
By exploiting CVE-2006-5218, attackers can cause a system crash, gain higher privileges, or read arbitrary kernel memory.
CVE-2006-5218 is a local vulnerability that requires an attacker to have local user access to the system.