CVE-2005-4779

NetBSD 2.0.2 - Local Privilege Escalation

Title source: llm
STIX 2.1

Description

verifiedexecioctl in verified_exec.c in NetBSD 2.0.2 calls NDINIT with UIO_USERSPACE rather than UID_SYSSPACE, which removes the functionality of the verified exec kernel subsystem and might allow local users to execute Trojan horse programs.

References (4)

Core 4
Core References
Various Sources x_refsource_confirm
http://releng.netbsd.org/cgi-bin/req-2-0.cgi?show=1988
Patch vdb-entry x_refsource_osvdb
http://www.osvdb.org/20725

Scores

EPSS 0.0007
EPSS Percentile 21.4%

Details

Status published
Products (3)
netbsd/netbsd 2.0
netbsd/netbsd 2.0.1
netbsd/netbsd 2.0.2
Published Dec 31, 2005
Tracked Since Feb 18, 2026