Vulnerabilities > CVE-2003-0955 - Local Malformed Binary Execution Denial of Service vulnerability in Openbsd 3.3/3.4

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
openbsd
exploit available

Summary

OpenBSD kernel 3.3 and 3.4 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code in 3.4 via a program with an invalid header that is not properly handled by (1) ibcs2_exec.c in the iBCS2 emulation (compat_ibcs2) or (2) exec_elf.c, which leads to a stack-based buffer overflow.

Vulnerable Configurations

Part Description Count
OS
Openbsd
2

Exploit-Db

  • descriptionOpenBSD (ibcs2_exec) Kernel Local Exploit. CVE-2003-0955. Local exploit for bsd platform
    idEDB-ID:118
    last seen2016-01-31
    modified2003-11-07
    published2003-11-07
    reporterScott Bartram
    sourcehttps://www.exploit-db.com/download/118/
    titleOpenBSD ibcs2_exec Kernel Local Exploit
  • descriptionOpenBSD 2.x - 3.3 exec_ibcs2_coff_prep_zmagic() Kernel Exploit. CVE-2003-0955. Local exploit for bsd platform
    idEDB-ID:125
    last seen2016-01-31
    modified2003-11-19
    published2003-11-19
    reporterSinan Eren
    sourcehttps://www.exploit-db.com/download/125/
    titleOpenBSD 2.x - 3.3 exec_ibcs2_coff_prep_zmagic Kernel Exploit