Vulnerabilities > CVE-2001-1559 - NULL Pointer Dereference vulnerability in Openbsd 2.9/3.0

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
openbsd
CWE-476
exploit available

Summary

The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mode values to the fdrelease function, which allows local users to cause a denial of service and trigger a null dereference.

Vulnerable Configurations

Part Description Count
OS
Openbsd
2

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionOpenBSD 2.x/3.0 User Mode Return Value Denial Of Service Vulnerability. CVE-2001-1559. Dos exploit for openbsd platform
idEDB-ID:21167
last seen2016-02-02
modified2001-12-03
published2001-12-03
reporterMarco Peereboom
sourcehttps://www.exploit-db.com/download/21167/
titleOpenBSD 2.x/3.0 - User Mode Return Value Denial of Service Vulnerability