CVE-2009-2793
NetBSD 5.0.1 - 'IRET' General Protection Fault Handling Privilege Escalation
Severity Score
4.6
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The kernel in NetBSD, probably 5.0.1 and earlier, on x86 platforms does not properly handle a pre-commit failure of the iret instruction, which might allow local users to gain privileges via vectors related to a tempEIP pseudocode variable that is outside of the code-segment limits.
El kernel en NetBSD, posiblemente 5.0.1 y anteriores, en plataformas x86 no gestiona adecuadamente el fallo de preasignación de la instrucción "iret", lo que permitiría a usuarios locales conseguir privilegios a través de vectores relacionados con la variable de pseudocódigo tempEIP que esta fuera de los limites de segmento de código.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2009-08-17 CVE Reserved
- 2009-09-16 First Exploit
- 2009-09-18 CVE Published
- 2023-05-12 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/archive/1/506531/100/0/threaded | Mailing List |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/33229 | 2009-09-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | <= 5.0.1 Search vendor "Netbsd" for product "Netbsd" and version " <= 5.0.1" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 0.8 Search vendor "Netbsd" for product "Netbsd" and version "0.8" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 0.9 Search vendor "Netbsd" for product "Netbsd" and version "0.9" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 1.0 Search vendor "Netbsd" for product "Netbsd" and version "1.0" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 1.1 Search vendor "Netbsd" for product "Netbsd" and version "1.1" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 1.2 Search vendor "Netbsd" for product "Netbsd" and version "1.2" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 1.2.1 Search vendor "Netbsd" for product "Netbsd" and version "1.2.1" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 1.3 Search vendor "Netbsd" for product "Netbsd" and version "1.3" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 1.3.1 Search vendor "Netbsd" for product "Netbsd" and version "1.3.1" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 1.3.2 Search vendor "Netbsd" for product "Netbsd" and version "1.3.2" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 1.3.3 Search vendor "Netbsd" for product "Netbsd" and version "1.3.3" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 1.5 Search vendor "Netbsd" for product "Netbsd" and version "1.5" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 1.5.1 Search vendor "Netbsd" for product "Netbsd" and version "1.5.1" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 1.5.2 Search vendor "Netbsd" for product "Netbsd" and version "1.5.2" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 1.5.3 Search vendor "Netbsd" for product "Netbsd" and version "1.5.3" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 1.6 Search vendor "Netbsd" for product "Netbsd" and version "1.6" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 1.6.1 Search vendor "Netbsd" for product "Netbsd" and version "1.6.1" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 1.6.2 Search vendor "Netbsd" for product "Netbsd" and version "1.6.2" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 2.0 Search vendor "Netbsd" for product "Netbsd" and version "2.0" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 2.0.1 Search vendor "Netbsd" for product "Netbsd" and version "2.0.1" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 2.0.2 Search vendor "Netbsd" for product "Netbsd" and version "2.0.2" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 2.0.3 Search vendor "Netbsd" for product "Netbsd" and version "2.0.3" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 2.1 Search vendor "Netbsd" for product "Netbsd" and version "2.1" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 3.0 Search vendor "Netbsd" for product "Netbsd" and version "3.0" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 3.0.1 Search vendor "Netbsd" for product "Netbsd" and version "3.0.1" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 3.0.2 Search vendor "Netbsd" for product "Netbsd" and version "3.0.2" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 3.1 Search vendor "Netbsd" for product "Netbsd" and version "3.1" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 4.0 Search vendor "Netbsd" for product "Netbsd" and version "4.0" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 4.0.1 Search vendor "Netbsd" for product "Netbsd" and version "4.0.1" | - |
Affected
| ||||||
Netbsd Search vendor "Netbsd" | Netbsd Search vendor "Netbsd" for product "Netbsd" | 5.0 Search vendor "Netbsd" for product "Netbsd" and version "5.0" | - |
Affected
|