2 Feb 2010 20:04
Updated: NetBSD Security Advisory 2010-001: File system module autoloading Denial of Service attack
NetBSD Security Officer <security-officer <at> NetBSD.org>
2010-02-02 19:04:18 GMT
2010-02-02 19:04:18 GMT
NetBSD Security Advisory 2010-001 ================================= Topic: File system module autoloading Denial of Service attack Version: NetBSD-current: affected prior to 2009-12-19 20:28:27 UTC NetBSD 5.0.1: not affected NetBSD 5.0: not affected NetBSD 4.0.*: not affected NetBSD 4.0: not affected Severity: Local Denial of Service Fixed: NetBSD-current: Dec 19, 2009 Please note that NetBSD releases prior to 4.0 are no longer supported. It is recommended that all users upgrade to a supported release. Abstract ======== A coding error in the NetBSD VFS code allows a local attacker to crash the local system by passing a soon-to-be-unmapped pointer as a file system name to the mount system call. Technical Details ================= When entering the mount_get_vfsops() function, the string "fstype",(Continue reading)
RSS Feed