|
|
|
![]() |
Vulnerability Note VU#314963OpenBSD kernel fails to properly check closed file descriptors "0-2" when running setuid programOverviewThe OpenBSD kernel does not adequately check file descriptors 0-2 prior to exec()ing setuid binaries. Other OS kernels may be vulnerable as well.I. DescriptionThe OpenBSD kernel does not adequately check file descriptors 0-2 prior to exec()ing setuid binaries. As a result, an attacker may be able to gain elevated privileges.II. ImpactA local attacker can gain root privileges.III. SolutionApply a patch from your vendor.OpenBSD patches are available from:
References
This document was written by Ian A. Finlay.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||