vendor:
Systrace
by:
Unknown
7.8
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Systrace
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2004-2170
CPE: a:netbsd:systrace
Platforms Tested: NetBSD, FreeBSD
2004
Systrace Privilege Escalation Vulnerability
The vulnerability allows a local attacker to gain root privileges on a vulnerable system by exploiting insufficient access validation in Systrace on NetBSD and the FreeBSD port by Vladimir Kotal. The attacker can use a specially crafted payload to restore privileges and execute arbitrary code.
Mitigation:
Apply the patch provided by the vendor or upgrade to a non-vulnerable version of Systrace.