Record summary

CVE-2003-0955 has a selected CVSS score of 4.6; EIP currently links 2 catalogued exploits.

Description

OpenBSD kernel 3.3 and 3.4 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code in 3.4 via a program with an invalid header that is not properly handled by (1) ibcs2_exec.c in the iBCS2 emulation (compat_ibcs2) or (2) exec_elf.c, which leads to a stack-based buffer overflow.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBOpenBSD - 'ibcs2_exec' Kernel Code ExecutionExploitDB exploitby Scott BartramNot analyzed1 file
ExploitDB

PoC details
ExploitDBOpenBSD 2.x < 3.3 - 'exec_ibcs2_coff_prep_zmagic()' kernel stack overflowExploitDB exploitby Sinan ErenNot analyzed1 file
ExploitDB

PoC details

References

7