CVE-2001-0268
Last modified
CVE-2001-0268 is a vulnerability of currently unknown severity. The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by creating a segment call gate in the Local Descriptor Table (LDT) with a target that specifies an arbitrary kernel address.. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by creating a segment call gate in the Local Descriptor Table (LDT) with a target that specifies an arbitrary kernel address.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netbsd | Netbsd | <= 1.5 |
| Openbsd | Openbsd | <= 2.8 |
References
- http://archives.neohapsis.com/archives/netbsd/2001-q1/0093.htmlPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/358960US Government Resource
- http://archives.neohapsis.com/archives/netbsd/2001-q1/0093.htmlPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/358960US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-0268?
How severe is CVE-2001-0268?
How do I fix CVE-2001-0268?
Are you affected by CVE-2001-0268?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
