CVE-2010-2530: Medium severity netbsd current vulnerability
Multiple integer signedness errors in smbsubr.c in the netsmb module in the kernel in NetBSD 5.0.2 and earlier, FreeBSD, and Apple Mac OS X allow local users to cause a denial of service (panic) via a negative size value in a /dev/nsmb ioctl operation, as demonstrated by a (1) SMBIOCLOOKUP or (2) SMBIOCOPENSESSION ioctl call.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2530?
CVE-2010-2530 is classified as a medium severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2010-2530?
To fix CVE-2010-2530, update to the latest version of NetBSD, FreeBSD, or macOS that contains patches for the vulnerability.
Which systems are affected by CVE-2010-2530?
CVE-2010-2530 affects NetBSD versions up to 5.0.2, various FreeBSD versions, and Apple Mac OS X.
What is the impact of CVE-2010-2530?
The impact of CVE-2010-2530 is a denial of service that can cause a system panic when handling negative size values in certain ioctl operations.
Can local users exploit CVE-2010-2530?
Yes, local users can exploit CVE-2010-2530 to trigger a denial of service condition.