CVE-2001-0993

NetBSD 1.3-1.5 - Denial of Service via sendmsg msg_controllen Length

Title source: llm
STIX 2.1

Description

sendmsg function in NetBSD 1.3 through 1.5 allows local users to cause a denial of service (kernel trap or panic) via a msghdr structure with a large msg_controllen length.

References (4)

Core 4
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_netbsd
http://archives.neohapsis.com/archives/netbsd/2001-q3/0102.html
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3088
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/6908
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/1910

Scores

EPSS 0.0006
EPSS Percentile 20.1%

Details

Status published
Products (9)
netbsd/netbsd 1.3
netbsd/netbsd 1.3.1
netbsd/netbsd 1.3.2
netbsd/netbsd 1.3.3
netbsd/netbsd 1.4
netbsd/netbsd 1.4.1
netbsd/netbsd 1.4.2
netbsd/netbsd 1.4.3
netbsd/netbsd 1.5
Published Jul 24, 2001
Tracked Since Feb 18, 2026