Permissions, Privileges, and Access Controls in NetBSD - #VU24470

 

Permissions, Privileges, and Access Controls in NetBSD - #VU24470

Published: January 21, 2020


Vulnerability identifier: #VU24470
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to absent access control mechanisms for SIOCGATHDIAG, SIOCSIFDESCR and SIOCGUMBINFO IOCTLs. A local unprivileged user can obtain sensitive information from network interfaces as well as set their description or diagnostic info.


Affected software

NetBSD

Remediation

Install updates from vendor's website.


External References

Related Security Bulletins