Vulnerabilities > CVE-2002-1420 - Unspecified vulnerability in Openbsd 3.0/3.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Integer signedness error in select() on OpenBSD 3.1 and earlier allows local users to overwrite arbitrary kernel memory via a negative value for the size parameter, which satisfies the boundary check as a signed integer, but is later used as an unsigned integer during a data copying operation.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 2 |
References
- http://marc.info/?l=bugtraq&m=102918817012863&w=2
- http://marc.info/?l=bugtraq&m=102918817012863&w=2
- http://www.iss.net/security_center/static/9809.php
- http://www.iss.net/security_center/static/9809.php
- http://www.kb.cert.org/vuls/id/259787
- http://www.kb.cert.org/vuls/id/259787
- http://www.osvdb.org/7554
- http://www.osvdb.org/7554
- http://www.securityfocus.com/bid/5442
- http://www.securityfocus.com/bid/5442