OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[sec-adv] NetBSD IBCS2 Kernel Memory Disclosure Vulnerability

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Thu Sep 18 2003 - 05:15:49 CDT


TITLE:
NetBSD IBCS2 Kernel Memory Disclosure Vulnerability

SECUNIA ADVISORY ID:
SA9769

VERIFY ADVISORY:
http://www.secunia.com/advisories/9769/

CRITICAL:
Less critical

IMPACT:
Exposure of system information, Exposure of sensitive information

WHERE:
Local system

OPERATING SYSTEM:
NetBSD 1.x

DESCRIPTION:
An information disclosure vulnerability has been identified in
NetBSD, which can be exploited by malicious, local users to gain
knowledge of content in kernel memory.

For more information:
SA9504

This only affects the 1.5 branch.

NOTE: You are only vulnerable if the kernel configuration file
contains "COMPAT_IBCS2".

SOLUTION:
NetBSD-1.5 branch dated later than August 28, 2003 is not vulnerable.

ORIGINAL ADVISORY:
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-013.txt.asc

OTHER REFERENCES:
SA9504:
http://www.secunia.com/advisories/9504/

----------------------------------------------------------------------

Secunia recommends that you verify all advisories you receive, by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

Contact details:
Web : http://www.secunia.com/
E-mail : supportsecunia.com
Tel : +45 7020 5144
Fax : +45 7020 5145

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------