|
NetBSD Repeated TIOSCTTY IOCTL Buffer Overflow Vulnerability
A call to TIOSCTTY will increment the hold count of a kernel structure shared between processes in the same session. Thus, repeated calls to TIOSCTTY will cause an internal buffer to be incremented indefinitely and overflow. The flaw will allow a local attacker to cause the memory structure to be freed prematurely. This may cause a kernel panic or cause faulty teminal sessions. |
|
|
Privacy Statement |