CVE-2002-2180
6.8
Vector
AV:L/AC:L/Au:S/C:C/I:C/A:C
Exploitability: 3.1 / Impact: 10.0
Source: NVD
Description
The setitimer(2) system call in OpenBSD 2.0 through 3.1 does not properly check certain arguments, which allows local users to write to kernel memory and possibly gain root privileges, possibly via an integer signedness error.
Affected (12)
References (8)
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.0/common/032_kerntime.patch (unsafe URL)
Source: cve@mitre.org
Patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.0/common/032_kerntime.patch (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.