First published: Sat Mar 10 2007(Updated: )
Integer overflow in the ktruser function in NetBSD-current before 20061022, NetBSD 3 and 3-0 before 20061024, and NetBSD 2 before 20070209, when the kernel is built with the COMPAT_FREEBSD or COMPAT_DARWIN option, allows local users to cause a denial of service and possibly gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetBSD current | =2.0 | |
NetBSD current | =2.0.1 | |
NetBSD current | =2.0.2 | |
NetBSD current | =2.0.3 | |
NetBSD current | =2.0.4 | |
NetBSD current | =2.1 | |
NetBSD current | =3.0.1 | |
NetBSD current | =4.0 | |
Microsoft Dynamics NAV | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1273 is classified as a moderate severity vulnerability due to the potential for denial of service and privilege escalation.
To fix CVE-2007-1273, update to a patched version of NetBSD that addresses the integer overflow issue.
CVE-2007-1273 affects NetBSD-current before 20061022, NetBSD 3 and 3-0 before 20061024, and NetBSD 2 before 20070209.
CVE-2007-1273 can only be exploited by local users, not remotely.
The potential impacts of CVE-2007-1273 include denial of service and possibly gaining elevated privileges on the system.