ilja.netric.org
http://ilja.netric.org/files/Unusual%20bugs%2023c3.pdf CVE-2007-0085
OpenBSD 3.x < 4.0 - 'vga_ioctl()' Local Privilege Escalation
Record summary
CVE-2007-0085 has a selected CVSS score of 6.0; EIP currently links 1 catalogued exploit.
Description
Unspecified vulnerability in sys/dev/pci/vga_pci.c in the VGA graphics driver for wscons in OpenBSD 3.9 and 4.0, when the kernel is compiled with the PCIAGP option and a non-AGP device is being used, allows local users to gain privileges via unspecified vectors, possibly related to agp_ioctl NULL pointer reference.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOpenBSD 3.x < 4.0 - 'vga_ioctl()' Local Privilege EscalationExploitDB exploitby Critical SecurityNot analyzed1 file
References
11[openbsd-cvs] 20070103 Re: CVS: cvs.openbsd.org: srcmailing list
http://marc.info/?l=openbsd-cvs&m=116781980706409&w=2 [openbsd-cvs] 20070103 CVS: cvs.openbsd.org: wwwmailing list
http://marc.info/?l=openbsd-cvs&m=116785923301416&w=2 23608Third-party advisory
http://secunia.com/advisories/23608 1017468vdb entry
http://securitytracker.com/id?1017468 [4.0] 007: SECURITY FIX: January 3, 2007Vendor advisory
http://www.openbsd.org/errata.html [3.9] 017: SECURITY FIX: January 3, 2007Vendor advisory
http://www.openbsd.org/errata39.html 32574vdb entry
http://www.osvdb.org/32574 ADV-2007-0043vdb entry
http://www.vupen.com/english/advisories/2007/0043 openbsd-vga-privilege-escalation(31276)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/31276 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-0085